Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Critical Flaw in ServiceNow AI Platform: A Threat to Enterprise Security


A critical vulnerability has been discovered in the ServiceNow AI Platform, allowing unauthenticated users to execute arbitrary code within the platform, posing a significant threat to enterprise security.

  • ServiceNow AI Platform has a critical security flaw (CVE-2026-6875) allowing unauthenticated users to execute arbitrary code.
  • Exploitation efforts target the same pre-authentication endpoint using HTTP POST requests, leading to code execution primitive.
  • Patches were released for specific versions in June, and additional technical specifics have been disclosed by Searchlight Cyber.
  • ServiceNow is enhancing instance security by restricting code that can run in sandbox contexts.
  • Clients are advised to apply fixes immediately to counter the threat and ensure platform integrity.
  • The vulnerability has significant implications for enterprises relying on the ServiceNow AI Platform, including unauthorized code execution and potential breaches.



  • A recent vulnerability discovered in the ServiceNow AI Platform has left cybersecurity experts and enterprises alike on high alert. The critical security flaw, designated as CVE-2026-6875 (CVSS score: 9.5), allows unauthenticated users to execute arbitrary code within the platform, posing a significant threat to enterprise security.

    According to Threat Intelligence firm Defused Cyber, the exploitation efforts are targeting the same pre-authentication endpoint ("/assessment_thanks.do") using HTTP POST requests. However, the sandbox-escape gadget leads to the same code execution primitive by a different route documented in the proof-of-concept (PoC) exploit.

    The vulnerability was reported on April 1, 2026, and patches were released by ServiceNow throughout June for specific versions - Brazil EA and Brazil GA, Australia Patch 2, Zurich Patch 7b and Zurich Patch 9, Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13. Searchlight Cyber has disclosed additional technical specifics about the issue.

    Adam Kues, a security researcher noted that besides rolling out a fix, ServiceNow is enhancing instance security by severely restricting the type of code that can run in sandbox contexts.

    In light of active exploitation efforts targeting self-hosted versions of the platform, customers are advised to apply the fixes if not already done. This is essential for countering the threat and ensuring the integrity of their ServiceNow AI Platform.

    The critical flaw has significant implications for enterprises relying on the ServiceNow AI Platform for various purposes, including but not limited to artificial intelligence applications and security. The potential consequences of this vulnerability include unauthorized code execution, which could lead to a complete compromise of the ServiceNow instance as well as all connected proxy servers.

    In conclusion, the recent discovery of the critical flaw in the ServiceNow AI Platform highlights the need for enterprises to prioritize cybersecurity and stay updated with the latest patches and security measures. It is imperative that organizations take proactive steps to secure their platforms against such threats to protect themselves from potential breaches.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Critical-Flaw-in-ServiceNow-AI-Platform-A-Threat-to-Enterprise-Security-ehn.shtml

  • https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-6875

  • https://www.cvedetails.com/cve/CVE-2026-6875/


  • Published: Tue Jul 21 03:11:28 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us