Attackers are actively exploiting a critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow's AI Platform, allowing unauthenticated access to self-hosted instances. The flaw, identified in the GlideRecord query API, enables attackers to bypass security sandboxes and execute arbitrary code, potentially leading to full system compromise. Developers and cybersecurity professionals must prioritize patching ServiceNow instances, as the vulnerability's rapid weaponization highlights the critical need for prompt security updates. An implication to watch is the increasing sophistication of supply chain attacks targeting widely used enterprise software.
Read the full article at Security Affairs
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





