Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw Found in ServiceNow AI Platform

A serious security weakness has been found in the ServiceNow AI platform that could allow attackers to run harmful software remotely. ServiceNow has released fixes for both hosted and self-hosted users. Small organisations using ServiceNow should ensure updates are applied promptly to avoid risk.

20 July 2026

Reference: CVE-2026-6875

1. What is being reported?

A critical vulnerability in the ServiceNow AI platform could let someone who is not logged in run malicious code inside the system. ServiceNow has fixed this by releasing security updates for all customers, including those who host the software themselves.

2. What this means in plain English

If your organisation uses ServiceNow, this flaw could let attackers take control of your system without needing a password. This could lead to data theft, disruption, or other serious problems. Applying the updates stops this from happening.

3. Could this affect a small business?

Small businesses and charities using ServiceNow, especially those using the AI features, could be affected if they have not applied the updates. Organisations not using ServiceNow or not using the AI platform are unlikely to be affected.

4. What to do now

  • Check if your organisation uses ServiceNow, particularly the AI platform.
  • Ask your IT provider or software supplier if the latest security updates for ServiceNow have been applied.
  • If you self-host ServiceNow, ensure you have installed the patches provided by ServiceNow.
  • Monitor for any unusual activity and report concerns to your IT support immediately.

5. Ask your IT provider

Has the latest security update for the ServiceNow AI platform vulnerability CVE-2026-6875 been applied to our systems?

6. Bottom line

Make sure your ServiceNow software is fully updated to protect against this serious security risk.

Information based on NVD, CISA KEV, and reputable security reporting.

Back to Vulnerability Briefs