Threat actors are actively exploiting a critical, unpatched vulnerability in the ServiceNow AI Platform, granting them the ability to execute arbitrary code on affected systems without any authentication, according to a warning from threat intelligence firm Defused Cyber.

The vulnerability, tracked as CVE-2026-6875, carries a severe CVSS score of 9.5. Its core danger lies in its nature as a sandbox escape flaw, a class of vulnerability that is particularly potent within AI environments. As detailed in a post on X, defenders are now facing confirmed in-the-wild exploitation campaigns targeting this issue.

The immediate risk is profound. Unlike many severe vulnerabilities, this one requires no user credentials, meaning attackers can discover and compromise susceptible ServiceNow instances via mass scanning. A successful exploit allows an unauthenticated user to break out of the platform's AI sandbox and run arbitrary code with the privileges of the underlying system.

ServiceNow, a dominant platform in enterprise IT service management and workflow automation, has increasingly integrated AI capabilities, such as Now Assist. A sandbox escape in this context uniquely threatens the integrity of AI models, the confidentiality of proprietary data they process, and the security of all interconnected internal systems that rely on the platform.

Patches for the vulnerability have been released by ServiceNow. The company's advisory, as referenced in the initial disclosure, urges immediate patching as the primary mitigation. Concurrently, security teams are strongly advised to audit and tighten network access controls on all ServiceNow instances to reduce public exposure and to review system logs for potential indicators of compromise associated with this CVE.

The rapid weaponization of this flaw highlights a maturing attacker focus on high-value SaaS and AI infrastructure. As noted in security analyses following the disclosure, the ubiquity of ServiceNow in enterprise workflows means the potential blast radius of this vulnerability is vast, making it a sector-wide concern.

This incident underscores a strategic imperative for organizations leveraging AI-integrated toolchains. The security of AI platform components must now be treated as a critical attack vector on par with traditional infrastructure. Defenders are urged to accelerate vulnerability response cycles and conduct a holistic review of their security posture around AI tools, emphasizing the need for robust sandboxing, strict access controls, and continuous monitoring.

The lack of detailed public information on which specific AI features or custom agent frameworks are most affected adds to the urgency. Organizations must prioritize applying all vendor patches without delay to mitigate a threat that is already being leveraged in the wild.


根據威脅情報公司 Defused Cyber 的警告,威脅行為者正積極利用 ServiceNow AI 平台一個嚴重且未經修補的漏洞,使他們能在無需任何認證的情況下,在受影響系統上執行任意代碼。

該漏洞被編錄為 CVE-2026-6875,CVSS 嚴重性評分為 9.5。其核心危險在於它屬於沙箱逃逸漏洞——這類漏洞在 AI 環境中尤為致命。X 平台上的一篇貼文詳述了此問題,防禦者現在正面對已確認的、針對此漏洞的在野利用活動。

即時風險極為深遠。與許多嚴重漏洞不同,此漏洞無需用戶憑證,意味著攻擊者可透過大量掃描發現並入侵易受攻擊的 ServiceNow 實例。成功利用此漏洞可讓未經驗證的用戶逃出平台的 AI 沙箱,並以底層系統的權限運行任意代碼。

ServiceNow 作為企業 IT 服務管理與工作流程自動化的主流平台,已逐步整合 AI 功能,例如 Now Assist。在此背景下,沙箱逃逸獨特地威脅到 AI 模型的完整性、其處理的專有數據的機密性,以及所有依賴該平台的互連內部系統的安全性。

ServiceNow 已發布該漏洞的補丁。根據初始揭露中引用的該公司公告,強烈敦促立即套用補丁作為主要緩解措施。同時,強烈建議安全團隊審計並收緊所有 ServiceNow 實例的網絡存取控制,以減少公開暴露,並檢查系統日誌中與此 CVE 相關的潛在入侵指標。

此漏洞被迅速武器化,突顯攻擊者日益關注高價值 SaaS 及 AI 基礎設施。正如揭露後的多份安全分析所指,ServiceNow 在企業工作流程中的普遍性意味著此漏洞的潛在衝擊範圍極廣,使其成為整個行業的關注點。

此次事件突顯了使用 AI 整合工具鏈的組織一項戰略必要性。AI 平台組件的安全性現必須被視為與傳統基礎設施同等重要的關鍵攻擊向量。防禦者應加速漏洞應對週期,並對其圍繞 AI 工具的安全態勢進行全面審查,強調需要穩健的沙箱機制、嚴格的存取控制以及持續監控。

由於公開資訊缺乏關於具體哪些 AI 功能或自訂代理框架最受影響的詳細細節,這增加了緊迫性。組織必須優先毫不延遲地套用所有供應商補丁,以緩解已在在野被利用的威脅。

新聞來源 / Original News Source