CyberSecurity News
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
AI summary
A critical security flaw in the ServiceNow AI Platform is being exploited by threat actors, according to Defused Cyber. The vulnerability, identified as CVE-2026-6875, has a CVSS score of 9.5 and allows an unauthenticated user to execute arbitrary code due to a sandbox escape issue. Patches for the flaw have been released. Defused Cyber has observed in-the-wild exploitation of this vulnerability. The flaw could enable unauthenticated code execution, posing a significant risk. Threat intelligence firm Defused Cyber shared its findings on the social media platform X.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

