AI workflow security

ServiceNow's AI Platform RCE Made Workflow Patch Proof Urgent

The news hook is July 20, 2026 reporting from BleepingComputer and Help Net Security that attackers have begun exploiting CVE-2026-6875, a critical pre-authentication ServiceNow AI Platform sandbox-escape RCE. Tenable's CVE page describes the flaw as critical, says it can let an unauthenticated user execute code within the ServiceNow platform in certain circumstances, and notes ServiceNow security updates for hosted and self-hosted customers. Searchlight Cyber's original research says ServiceNow mitigated hosted instances after an April report and later patched the underlying issue. The support-ops issue is immediate: CRM, ITSM, helpdesk, AI workflow, and outsourced operations buyers need proof for instance exposure, patch status, workflow blast radius, connected-app tokens, log review, and closure evidence.

Synthetic editorial image of support operations and security staff reviewing unbranded workflow dashboards, patch evidence, and access boundaries.
Editorial image: synthetic representative support-ops scene, not a photo of the named company or news event.

Direct answer

ServiceNow CVE-2026-6875 AI Platform workflow risk map: what CRM buyers should take from it

BleepingComputer reported on July 20, 2026 that attackers had begun exploiting CVE-2026-6875, a critical ServiceNow AI Platform vulnerability. Tenable's CVE page describes the flaw as a critical remote code execution issue that can let an unauthenticated user execute code within the ServiceNow platform in certain circumstances, with a CVSS v3 base score of 9.8 and a CVSS v4 base score of 9.5. ServiceNow's advisory says security updates were deployed to hosted instances and provided for self-hosted customers and partners. Support-ops buyers should respond by proving instance exposure, patch status, workflow blast radius, token rotation, log review, and incident closure before assuming AI workflow platforms are contained.

Published 7/21/2026. News event: 7/20/2026.

What happened

  • BleepingComputer reported on July 20, 2026 that attackers had begun exploiting CVE-2026-6875 in the ServiceNow AI Platform, citing threat intelligence firm Defused.
  • Searchlight Cyber's research says it reported the sandbox-escape issue to ServiceNow on April 1, 2026, and that the issue was assigned CVE-2026-6875.
  • Tenable's CVE page describes CVE-2026-6875 as a critical remote code execution vulnerability that can enable unauthenticated code execution within the ServiceNow platform in certain circumstances.
  • Tenable says ServiceNow deployed a security update to hosted instances and provided relevant updates to self-hosted customers and partners.
  • BleepingComputer also reported ServiceNow's statement that it had not observed evidence that the reported activity was related to ServiceNow-hosted instances, while encouraging customers to apply relevant patches.

Why this is trending

  • The vulnerability hits an enterprise workflow platform that can sit close to tickets, approvals, assets, user records, AI actions, and customer operations.
  • The active-exploitation reporting arrived days after public patch availability, making patch proof more urgent than generic vendor assurance.
  • For support operations, the issue is not only code execution. It is whether a compromised workflow platform can expose tickets, trigger automations, abuse connected apps, or disrupt service processes.

The CRM Costs take

A support-ops buyer should not treat this as only a security-team CVE ticket. The buyer needs an AI Platform Workflow Risk Map: instance inventory, hosted versus self-hosted exposure, patch family evidence, mitigation status, workflow blast-radius review, connected-app token rotation, logs, customer-data scope, and closure proof.

AI Platform Workflow Risk Map

A support-ops buyer framework for validating AI workflow platform exposure, patch proof, workflow blast radius, integration access, log review, and closure evidence after a critical platform vulnerability.

AI Platform Workflow Risk Map framework visual
Cost layer
Buyer question
Risk signal and next step
Instance exposure
Which hosted, self-hosted, partner, sandbox, and integration-facing instances could process support or AI workflows?
The organization tracks production only and forgets partner, test, self-hosted, or externally reachable workflow surfaces.

Create an instance inventory with owner, release family, hosting model, network exposure, AI feature use, and support-workflow scope.

Patch proof
Can the team prove every affected instance is on a patched release or protected by vendor-deployed mitigations?
Leaders accept 'vendor patched it' without matching the statement to each tenant, family release, self-hosted instance, or partner environment.

Collect family release, patch, hotfix, mitigation, update time, owner signoff, and retest evidence for every relevant instance.

Workflow blast radius
Which support, ITSM, CRM, approval, AI, and customer-data workflows could be touched if the platform were abused?
Security closes the CVE while operations cannot say which tickets, approvals, records, or automations mattered.

Map exposed workflows, data classes, automation actions, external customers, privileged roles, and downstream systems.

Connected-app access
Which integrations, API users, tokens, and workflow credentials should be rotated or reviewed after exposure?
The patch lands but stale integration tokens, proxy accounts, and delegated app permissions remain untouched.

Review connected apps, OAuth grants, API users, secrets, proxies, service accounts, and privileged workflow credentials.

Log and detection review
Can the team show whether exploitation attempts touched the instance, suspicious routes, or workflow actions?
There is no queryable audit trail for unusual script paths, user creation, workflow changes, exports, or integration calls.

Run log searches for exploit indicators, unusual platform actions, changed workflows, new users, exports, and high-risk API calls.

Closure evidence
What proves the incident is closed from an operations, customer-data, and workflow-continuity perspective?
The vulnerability ticket is marked fixed without retests, customer-data scope, token review, or owner signoff.

Keep closure evidence with patches, retests, log review, token rotation, data-scope decision, customer notice decision, and next audit date.

What buyers should do next

Step 1 Inventory every ServiceNow AI Platform, workflow, support, ITSM, partner, and self-hosted surface tied to customer or internal operations.
Step 2 Match every instance to hosted mitigation proof, patch family, hotfix, release version, and owner signoff.
Step 3 Map which workflows, records, AI actions, approvals, integrations, and support queues would matter if the platform were compromised.
Step 4 Review API users, connected apps, OAuth grants, service accounts, and workflow credentials for rotation or restriction.
Step 5 Search logs for suspicious access, script paths, workflow changes, exports, new users, and high-risk integration calls.
Step 6 Close the issue only after patch retests, blast-radius review, token handling, customer-data decision, and executive owner signoff.

Buyer FAQs

What is CVE-2026-6875?

CVE-2026-6875 is a critical ServiceNow AI Platform sandbox-escape remote code execution vulnerability. Tenable describes it as enabling unauthenticated code execution within the platform in certain circumstances.

Why does this matter to support operations?

ServiceNow-style workflow platforms often connect tickets, approvals, customer records, ITSM actions, AI workflows, and integrations. A patch gate should include workflow blast radius and integration access, not only version status.

What proof should CRM and support buyers request?

Ask for instance inventory, patch or mitigation proof, release family, workflow blast-radius review, connected-app and token review, log searches, customer-data scope, and closure evidence.