A critical remote code execution vulnerability that was recently patched in the ServiceNow AI platform is reportedly being exploited in the wild.
The security hole is tracked as CVE-2026-6875 and it has been described as a sandbox escape issue that an unauthenticated attacker can exploit in certain circumstances to execute arbitrary code.
When it announced the availability of patches on July 14, ServiceNow said a security update addressing the vulnerability had been deployed to hosted instances. However, self-hosted customers have to install the patches themselves.
On the same day, cybersecurity firm Searchlight Cyber disclosed technical details and showed how the vulnerability can be exploited.
Threat intelligence firm Defused reported on July 18 that it had seen in-the-wild exploitation of CVE-2026-6875, leveraging information Searchlight Cyber had released.







