Multiple outlets report that threat actors are exploiting a critical vulnerability in the ServiceNow AI Platform tracked as CVE-2026-6875. Threat intelligence firm Defused says it is observing in-the-wild exploitation of the flaw. The vulnerability is described as a pre-authentication remote code execution (RCE) issue that allows unauthenticated attackers to escape ServiceNow’s script sandbox and execute code on a targeted instance. Help Net Security and other sources describe it as a code injection vulnerability affecting the ServiceNow AI platform.
Researchers at Searchlight Cyber are reported to have discovered the issue and informed ServiceNow in early April 2026. SecurityWeek reports that exploitation activity is seen within days after the vulnerability’s disclosure, indicating rapid adoption by attackers after patches became available. The Hacker News also cites Defused’s assessment, including a high CVSS score (9.5) for the vulnerability.
Across the reports, the main point is that CVE-2026-6875 is being actively exploited and enables unauthenticated attackers to achieve remote code execution via sandbox escape.