Attackers are actively exploiting CVE-2026-6875, a critical code execution vulnerability in ServiceNow's AI Platform. Threat intelligence firm Defused confirmed the attacks are underway.
■ Active Attacks Confirmed
Cybersecurity researchers at Defused have identified active exploitation of CVE-2026-6875 in ServiceNow's AI Platform. The vulnerability allows unauthenticated attackers to execute arbitrary code on affected systems.
■ Vulnerability Details
The flaw exists in ServiceNow's AI Platform and carries a critical severity rating. The vulnerability enables remote code execution without requiring authentication, making it particularly dangerous for organizations running vulnerable instances.
■ Immediate Risk
ServiceNow customers using the AI Platform are at immediate risk. The active exploitation indicates threat actors have developed working attack code and are actively targeting systems. Organizations should assume attackers are scanning for and compromising vulnerable deployments.
■ Required Actions
ServiceNow has released patches addressing the vulnerability. Organizations should prioritize applying these updates immediately. Those unable to patch quickly should implement network-level restrictions to limit access to affected ServiceNow instances.
■ Broader Context
This marks another critical vulnerability in enterprise software with active exploitation. ServiceNow platforms are widely deployed across large organizations, making them valuable targets for attackers seeking network access and data theft.
■ Next Steps
Organizations should:
- Audit current ServiceNow deployments for vulnerable versions
- Apply available patches without delay
- Review access logs for signs of exploitation
- Monitor for suspicious AI Platform activity
Defused's disclosure comes as enterprises face increasing pressure from attackers targeting enterprise platforms for initial access into corporate networks.
A child sexual abuse survivor has filed a lawsuit against Elon Musk's AI company, alleging that Grok generated new illegal pornographic images using pictures of her abuse. Musk denied awareness of the chatbot producing such content.
A UNICEF survey of 21,000 internet-using children across 21 countries found nearly one in five experienced tech-facilitated sexual exploitation and abuse. The report reveals a critical gap in reporting, with less than 1% of cases reaching authorities.
A massive data breach at an unspecified car rental company exposed customer driver's licenses and personal information within hours of rental. The FBI is investigating the incident as data stolen from customers appears for sale online.
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin exposes WordPress sites to remote code execution and complete takeover by unauthenticated attackers.