``` A critical security flaw in the ServiceNow AI Platform, tracked as CVE-2026-6875, is now under active exploitation by malicious actors, marking a severe escalation in the threat landscape for organizations relying on the widely-used platform. Security intelligence firm Defused disclosed that unauthenticated attackers are leveraging the vulnerability to achieve remote code execution, potentially leading to full system compromise.

The flaw, which received a critical CVSS severity score between 9.8 and 10.0, presents a significant risk due to its unauthenticated nature. This means attackers can exploit it without any credentials, making automated scanning and widespread attacks highly feasible. The primary danger lies in the potential for remote code execution, which could grant an intruder deep access to and control over affected ServiceNow instances.

According to reporting by BleepingComputer, the development follows an initial patch release by ServiceNow in May 2026. The lag between the patch and the observed exploitation underscores a critical window of exposure for organizations that have not yet implemented the updates. It remains unclear whether exploitation attempts began before the public disclosure in July, leaving a potential period of stealthy compromise unknown.

Defused's confirmation of active exploitation shifts the posture of this vulnerability from a theoretical risk to an urgent, ongoing threat. Threat actors are actively scanning for and weaponizing the flaw, necessitating swift defensive action from IT and security teams.

The recommended response requires a multi-faceted approach. The foremost priority is to apply the vendor-supplied security patches without delay. Beyond patching, organizations should implement enhanced monitoring across their networks to detect any indicators of compromise or suspicious activity targeting their ServiceNow deployments. Specifically, security teams should review ServiceNow audit logs for unexpected processes or commands. Furthermore, ensuring robust network segmentation can help contain and limit the potential damage of a successful breach, preventing lateral movement within a corporate environment.

This incident highlights the perpetual arms race between software vendors and threat actors, especially concerning high-value platforms like ServiceNow. These platforms often serve as a central hub for critical IT services, HR workflows, and business operations, meaning a successful compromise could expose vast troves of sensitive data and disrupt core enterprise functions. The urgent call to action serves as a reminder of the importance of a disciplined vulnerability management program, including prompt patch application, to mitigate risks from actively exploited flaws.


ServiceNow AI 平台中一個關鍵安全漏洞(編號為 CVE-2026-6875)現正被惡意行為者積極利用,這標誌著依賴這款廣泛使用平台的組織所面臨的威脅態勢嚴重升級。網絡安全情報公司 Defused 披露,未經認證的攻擊者正利用該漏洞實現遠端程式碼執行,可能導致系統完全被入侵。

該漏洞的 CVSS 最嚴重評分介乎 9.8 至 10.0,由於其無需認證的特性,帶來重大風險。這意味著攻擊者無需任何憑證即可利用它,使自動化掃描和大規模攻擊變得高度可行。主要危險在於可能實現遠端程式碼執行,這將賦予入侵者深度訪問及控制受影響 ServiceNow 實例的能力。

根據 BleepingComputer 的報導,此事件發生在 ServiceNow 於 2026 年 5 月發布初步補丁之後。補丁發布與觀測到的利用之間的時間差,突顯了尚未實施更新的組織面臨的關鍵暴露窗口。目前尚不清楚利用嘗試是否始於 7 月公開披露之前,這留下了一段潛在的、未知的隱蔽入侵期。

Defused 將此漏洞從理論風險轉變為緊急且持續的威脅,確認了其正被積極利用。威脅行為者正主動掃描並武器化此漏洞,迫使 IT 和安全團隊迅速採取防禦行動。

建議的應對措施需要多管齊下。首要任務是毫不延遲地套用供應商提供的安全補丁。除了補丁,組織應在其整個網絡實施強化監控,以偵測任何針對其 ServiceNow 部署的入侵指標或可疑活動。具體而言,安全團隊應檢查 ServiceNow 審計日誌,查找意外的進程或命令。此外,確保穩健的網絡分段有助於控制並限制成功入侵的潛在損害,防止攻擊在企業環境內橫向移動。

此事件凸顯了軟件供應商與威脅行為者之間永無止境的攻防競賽,尤其涉及像 ServiceNow 這類高價值平台。這些平台通常充當關鍵 IT 服務、人力資源流程和業務營運的樞紐,意味著一次成功的入侵可能暴露大量敏感數據並中斷核心企業功能。緊急的行動呼籲提醒我們,必須建立一套嚴格的漏洞管理計劃,包括及時套用補丁,以減輕正遭積極利用的漏洞所帶來的風險。

新聞來源 / Original News Source