ServiceNow AI Platform Hit by Exploitation of Major Security Flaw

Hackers exploit a critical bug in the ServiceNow AI Platform, affecting workflows across major companies. Immediate action is advised for self-hosted users.

AI2Day Newsdesk· 2 min read
Close-up, editorial news-photography style, of a single illuminated server rack panel in a darkened data centre, with amber and red indicator lights casting a f
Share

Key points

  • Attackers began exploiting a critical ServiceNow AI Platform flaw, CVE-2026-6875, in live attacks starting on Friday, July 21, 2023.
  • ServiceNow hosts more than 100 billion workflows a year and is used by 85% of Fortune 500 companies.
  • ServiceNow released security patches on July 13, 2023, but exploitation began a week later.
  • Defused, a threat intelligence firm, confirmed the attacks, first reported by ThreatVectr.

A critical security flaw in the ServiceNow AI Platform, formerly known as the Now Platform, is under active exploitation by cybercriminals. This flaw, tracked as CVE-2026-6875, allows attackers to bypass authentication and execute their own code on the server. In simpler terms, attackers can break into the system without needing a username or password, potentially controlling sensitive data stored within.

The issue was first reported by ThreatVectr, revealing that attackers began targeting the flaw on Friday, July 21, 2023. This news follows ServiceNow's release of security patches on July 13, which were intended to address the vulnerability. The company advises any customers using self-hosted instances to apply these updates immediately.

Threat intelligence firm Defused noticed these attacks in the wild, confirming that they align with a previously discovered security gap in the platform. This gap was initially detected by Searchlight Cyber, who reported it to ServiceNow on April 1. The flaw allows attackers to exploit a specific web address, /assessment_thanks.do, which should not be accepting outside commands.

ServiceNow describes the attack as complex, requiring skill to execute. However, that hasn’t deterred attackers from trying and succeeding. Despite this activity, ServiceNow's public advisory currently states they are not aware of any active exploitation against their instances, a statement yet to be updated with the latest findings.

What should businesses using ServiceNow do?

If you manage a self-hosted instance of ServiceNow, apply the security patches released on July 13 immediately. Check your server logs for any unusual access attempts to /assessment_thanks.do, especially from July 21 onward. If you detect any unauthorized access, consider rotating any credentials or API tokens that were potentially exposed. For those using ServiceNow's hosted services, confirm with your account representative that the patch has been applied and ask for written confirmation of the date it was implemented.

ServiceNow is a significant player in enterprise software, with its platform handling over 100 billion workflows annually across 85% of Fortune 500 companies. The security of HR records, IT tickets, procurement details, and customer service logs, among other sensitive information, depends heavily on maintaining the integrity of these systems.

The urgency to act cannot be overstated. Companies must ensure they are protected against this vulnerability to safeguard their operations and data.

© 2026 AI2Day