A critical remote code execution vulnerability in ServiceNow's AI Platform (CVE-2026-6875) has moved from theoretical threat to active exploitation within days of patches becoming available. Discovered by Searchlight Cyber in April and disclosed publicly on July 13th, the flaw allows unauthenticated attackers to escape the platform's sandbox and execute arbitrary code—a particularly severe attack vector given that ServiceNow processes over 100 billion workflows annually across 85% of Fortune 500 companies. Threat intelligence firm Defused confirmed active exploitation by Friday, just one week after ServiceNow released patches, with attackers already adapting their payloads to bypass the documented proof-of-concept. Notably, ServiceNow's official advisory still claims no awareness of active exploitation, creating a dangerous lag between threat reality and vendor communication that leaves patching decisions ambiguous for teams still evaluating urgency.
For CX teams relying on ServiceNow for workflow automation, ticketing integration, or AI-driven customer interactions, this vulnerability represents a direct operational and compliance risk. The sandbox-escape mechanism means attackers could potentially access customer data, manipulate workflows, or inject malicious logic into the systems that orchestrate your support operations—particularly concerning given ServiceNow's deep integration with enterprise customer data pipelines. The question becomes acute for teams already leveraging ServiceNow's AI capabilities: how many of your critical customer-facing workflows depend on this platform, and do you have visibility into whether your instance has been patched? The speed of exploitation also underscores a broader pattern affecting AI infrastructure; 54% of enterprises have already experienced an AI agent incident, suggesting that security teams are consistently outpaced by both vulnerability disclosure timelines and attacker adaptation.
Immediate action is non-negotiable: verify patch status across all ServiceNow instances, prioritise self-hosted deployments (which received patches later than hosted instances), and audit access logs for the vulnerable `/assessment_thanks.do` endpoint that Defused identified as the attack vector. Beyond immediate remediation, this incident should trigger a broader review of how your organisation validates security claims from platform vendors—ServiceNow's delayed acknowledgement of active exploitation highlights the risk of relying solely on vendor advisories rather than threat intelligence feeds. For teams considering deeper AI integration into customer workflows, this serves as a reminder that platform security posture must be a continuous evaluation criterion, not a one-time vendor assessment.
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]