What Happened
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. Patches for the flaw were
Why It Matters
Report facts: The article describes active in-the-wild exploitation of CVE-2026-6875, a critical (CVSS 9.5) sandbox escape in the ServiceNow AI Platform that allows an unauthenticated attacker to execute arbitrary code within a ServiceNow instance, impacting both hosted and self-hosted environments.[1][2][3][4][5] The vulnerability is a server-side code injection / sandbox escape RCE, reachable over the network without authentication or user interaction, and has been patched in specific ServiceNow family releases.[1][2][4][5] RealGround analysis: This is a SaaS AI platform compromise risk, not a prompt-injection issue, and it directly affects the AI layer underpinning enterprise workflows and integrations.[4] Organizations relying on ServiceNow AI Platform should treat this as an AI supply-chain incident: immediately verify patch levels, restrict exposure of AI endpoints, and review logs, scripts, and integrations for unauthorized changes or lateral movement via MID servers or proxies.[2][3][4][5]
RealGround Analysis
This signal maps to SaaS AI risk. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html
