
Attackers have begun actively exploiting a critical vulnerability in the ServiceNow AI Platform — the software that powers more than 100,000 enterprise applications and runs over 100 billion automated workflows each year, including HR portals, IT service desks, and business operations at 85% of Fortune 500 companies. The flaw, tracked as CVE-2026-6875, allows an unauthenticated attacker to break out of the platform’s security sandbox and execute arbitrary code remotely. ServiceNow released a patch on July 13, but exploitation started just days later on July 18, according to threat intelligence firm Defused.
The real-world impact is significant: any unpatched ServiceNow instance exposed to the internet is at risk of being fully compromised without the attacker needing any credentials. Discovered by Searchlight Cyber on April 1 and privately reported to ServiceNow, the vulnerability has now had a working proof-of-concept published publicly, which is driving the wave of attacks. Organizations that have not yet applied the July 13 update are running on borrowed time.
How to check if you’re affected
Affected versions include all ServiceNow AI Platform (formerly Now Platform) releases prior to the July 13, 2026 security update that patches CVE-2026-6875.
What to do:
- Confirm your ServiceNow version. Log in to your ServiceNow instance as an admin, go to System Diagnostics > Stats, and check the build version. Compare it against the July 13 patch notes in ServiceNow’s release documentation.
- Apply the patch immediately. ServiceNow urges all customers to upgrade to a patched release as soon as possible. If your organization manages its own ServiceNow instance, treat this as an emergency change.
- Check for signs of compromise. Review your ServiceNow instance logs for unexpected script executions, unusual API calls, or new admin accounts created after July 18. If you find anything suspicious, contact your security team before continuing to use the platform.
- If you use ServiceNow through an employer, flag this to your IT or security team and ask whether the patch has been applied.
