ServiceNow Patches Three Critical AI Platform Flaws
ServiceNow’s AI platform connects enterprise data, workflows and generative artificial intelligence services, making flaws in its underlying components potentially far-reaching. Remote code execution and injection bugs can allow attackers to run unauthorized commands, manipulate applications or gain access to sensitive information. A score of 10.0 under the Common Vulnerability Scoring System represents the highest severity level, putting the vulnerabilities at the top of security teams’ remediation queues.
ServiceNow issued updates for three vulnerabilities carrying CVSS scores of 10.0, including remote code execution and injection flaws. Under certain deployment or configuration conditions, an attacker could exploit the weaknesses remotely without first authenticating, according to the company’s advisory. ServiceNow urged customers to install the available fixes promptly, review affected systems and monitor for suspicious activity; the information provided did not specify the advisory’s publication date or individual vulnerability identifiers.
All Coverage
1 original reportsThe Backstory
The history behind this eventServiceNow Patches Critical AI Platform RCE as Exploitation Emerges
ServiceNow AI Platform, formerly called Now Platform, is a cloud service that embeds AI, data and automation in core business workflows. The company says it processes more than 100 billion workflows a year and underpins over 100,000 enterprise AI applications at 85% of Fortune 500 companies. CVE-2026-6875, rated critical at 9.5 under CVSS 4.0, lets an unauthenticated attacker escape a script sandbox and potentially create administrators, extract records and execute shell commands on connected proxy servers.
ServiceNow disclosed the flaw on July 13, 2026, and issued patches to self-hosted customers and partners after deploying mitigations to cloud instances within 24 hours of Searchlight Cyber's April 1 report. Threat-intelligence firm Defused said it first observed in-the-wild exploitation on July 17, targeting the /assessment_thanks.do endpoint through a route different from the published proof of concept. ServiceNow said on July 20 it had found no evidence involving company-hosted instances, while urging all customers to apply the relevant patches.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →