TL;DR

what: Threat actors are actively exploiting CVE-2026-6875, a critical (CVSS 9.5) sandbox escape in the ServiceNow AI Platform that allows unauthenticated arbitrary code execution via a pre-auth endpoint.

impact: Successful exploitation yields complete compromise of the ServiceNow instance and all connected proxy servers, exposing ITSM data, credentials, and integrations across the environment.

fix: Apply the June 2026 ServiceNow patches now: Brazil EA/GA, Australia Patch 2, Zurich Patch 7b or 9, or Yokohama Patch 12 Hot Fix 1b or Patch 13.

who: Every organization running a self-hosted ServiceNow instance on an unpatched release is exposed to an unauthenticated, PoC-armed attack; ServiceNow-hosted customers should confirm patch status regardless.