
CVE-2026-6875: ServiceNow AI Platform — Unauthenticated RCE Risk (July 2026)
CVE-2026-6875 — ServiceNow AI Platform
CVE-2026-6875 is a critical vulnerability in ServiceNow’s AI platform that allows unauthenticated remote code execution (RCE). The flaw is not currently known to be exploited in the wild, but its severity and pre-authentication nature demand immediate attention. No CVSS score is published, but the vendor rates it as critical.
Attack Vector
Attackers can exploit CVE-2026-6875 remotely, without authentication, to execute arbitrary code on vulnerable ServiceNow AI platform instances. The vulnerability is triggered via crafted network requests sent to exposed endpoints, requiring no user interaction or valid credentials. There are no public indicators of compromise (IOCs) at this time, but exploitation would likely result in unauthorized code execution, lateral movement, and potential data compromise.
Who Is at Risk
Organizations running ServiceNow’s AI platform are directly affected. The vulnerability impacts all unpatched deployments globally, regardless of environment. Fortinet and Ivanti also released patches for related vulnerabilities (CVE-2026-14902, CVE-2026-14903), but only ServiceNow’s issue is rated critical and allows unauthenticated RCE. Confirmed affected vendors include ServiceNow, Fortinet, and Ivanti.
Patch & Mitigate
- Patch: Apply the official ServiceNow security patch released July 15, 2026. Check vendor advisories for exact version details and update immediately.
- Workaround: No viable workaround is available. Restrict network access to ServiceNow AI platform endpoints as a temporary measure if patching is delayed.
- Detect: Monitor logs for unusual or unauthorized requests to AI platform endpoints, especially from external or untrusted sources. Watch for unexpected process launches or privilege escalations on affected servers.
MITRE ATT&CK
- TA0001 — Initial Access: Attackers leverage exposed endpoints to gain initial foothold without authentication.
- T1190 — Exploit Public-Facing Application: The vulnerability is exploited via network requests to public-facing ServiceNow AI platform services.
Source: https://www.securityweek.com/vulnerabilities-patched-by-fortinet-ivanti-servicenow/
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

