bleeping-computer · Crawled Jul 20, 2026

Critical ServiceNow code execution flaw now exploited in attacks

1 IoCs
Read original article ↗

AI Summary

Attackers are actively exploiting a critical remote code execution vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, allowing unauthenticated threat actors to escape the sandbox and execute arbitrary code. The flaw was patched on July 13, 2026, but exploitation was confirmed in the wild just days later. Despite ServiceNow not officially acknowledging active exploitation, threat intelligence firm Defused has observed attack attempts leveraging the same endpoint used in the vulnerability proof-of-concept.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain assessment_thanks[.]do Details →