:

SERVICENOW FLAW UNDER ACTIVE EXPLOITATION

SECURITY DESK1 MIN READ
MON, JUL 20, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Attackers are actively exploiting CVE-2026-6875, a critical code execution vulnerability in ServiceNow's AI Platform. Threat intelligence firm Defused confirmed the attacks are underway.

■ Active Attacks Confirmed Cybersecurity researchers at Defused have identified active exploitation of CVE-2026-6875 in ServiceNow's AI Platform. The vulnerability allows unauthenticated attackers to execute arbitrary code on affected systems. ■ Vulnerability Details The flaw exists in ServiceNow's AI Platform and carries a critical severity rating. The vulnerability enables remote code execution without requiring authentication, making it particularly dangerous for organizations running vulnerable instances. ■ Immediate Risk ServiceNow customers using the AI Platform are at immediate risk. The active exploitation indicates threat actors have developed working attack code and are actively targeting systems. Organizations should assume attackers are scanning for and compromising vulnerable deployments. ■ Required Actions ServiceNow has released patches addressing the vulnerability. Organizations should prioritize applying these updates immediately. Those unable to patch quickly should implement network-level restrictions to limit access to affected ServiceNow instances. ■ Broader Context This marks another critical vulnerability in enterprise software with active exploitation. ServiceNow platforms are widely deployed across large organizations, making them valuable targets for attackers seeking network access and data theft. ■ Next Steps Organizations should: - Audit current ServiceNow deployments for vulnerable versions - Apply available patches without delay - Review access logs for signs of exploitation - Monitor for suspicious AI Platform activity Defused's disclosure comes as enterprises face increasing pressure from attackers targeting enterprise platforms for initial access into corporate networks.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A Unicode block invisible to human readers has transitioned from an academic curiosity used to test AI systems into an active tool for spammers. The technique exploits characters that machines process but humans cannot see.

1H AGOAI Desk

A study found that 86% of licensed British gambling websites violate GDPR privacy requirements, using deceptive cookie banners to track users before obtaining consent.

3H AGOSecurity Desk

Berlin's government is intensively reviewing 5.79TB of state data released by ransomware group Rhysida after refusing to pay a ransom demand. The leaked files reportedly contain sensitive information on national defense and threat response plans.

18H AGOIndustry Desk

Cybercriminals are exploiting thousands of compromised small-business websites to distribute ClickFix malware payloads stored in smart contracts on the BNB Smart Chain, amplifying the reach of a known threat.

21H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.