Direct answer
ServiceNow CVE-2026-6875 AI Platform workflow risk map: what CRM buyers should take from it
BleepingComputer reported on July 20, 2026 that attackers had begun exploiting CVE-2026-6875, a critical ServiceNow AI Platform vulnerability. Tenable's CVE page describes the flaw as a critical remote code execution issue that can let an unauthenticated user execute code within the ServiceNow platform in certain circumstances, with a CVSS v3 base score of 9.8 and a CVSS v4 base score of 9.5. ServiceNow's advisory says security updates were deployed to hosted instances and provided for self-hosted customers and partners. Support-ops buyers should respond by proving instance exposure, patch status, workflow blast radius, token rotation, log review, and incident closure before assuming AI workflow platforms are contained.
Published 7/21/2026. News event: 7/20/2026.
What happened
- BleepingComputer reported on July 20, 2026 that attackers had begun exploiting CVE-2026-6875 in the ServiceNow AI Platform, citing threat intelligence firm Defused.
- Searchlight Cyber's research says it reported the sandbox-escape issue to ServiceNow on April 1, 2026, and that the issue was assigned CVE-2026-6875.
- Tenable's CVE page describes CVE-2026-6875 as a critical remote code execution vulnerability that can enable unauthenticated code execution within the ServiceNow platform in certain circumstances.
- Tenable says ServiceNow deployed a security update to hosted instances and provided relevant updates to self-hosted customers and partners.
- BleepingComputer also reported ServiceNow's statement that it had not observed evidence that the reported activity was related to ServiceNow-hosted instances, while encouraging customers to apply relevant patches.
Why this is trending
- The vulnerability hits an enterprise workflow platform that can sit close to tickets, approvals, assets, user records, AI actions, and customer operations.
- The active-exploitation reporting arrived days after public patch availability, making patch proof more urgent than generic vendor assurance.
- For support operations, the issue is not only code execution. It is whether a compromised workflow platform can expose tickets, trigger automations, abuse connected apps, or disrupt service processes.
The CRM Costs take
A support-ops buyer should not treat this as only a security-team CVE ticket. The buyer needs an AI Platform Workflow Risk Map: instance inventory, hosted versus self-hosted exposure, patch family evidence, mitigation status, workflow blast-radius review, connected-app token rotation, logs, customer-data scope, and closure proof.
AI Platform Workflow Risk Map
A support-ops buyer framework for validating AI workflow platform exposure, patch proof, workflow blast radius, integration access, log review, and closure evidence after a critical platform vulnerability.
Create an instance inventory with owner, release family, hosting model, network exposure, AI feature use, and support-workflow scope.
Collect family release, patch, hotfix, mitigation, update time, owner signoff, and retest evidence for every relevant instance.
Map exposed workflows, data classes, automation actions, external customers, privileged roles, and downstream systems.
Review connected apps, OAuth grants, API users, secrets, proxies, service accounts, and privileged workflow credentials.
Run log searches for exploit indicators, unusual platform actions, changed workflows, new users, exports, and high-risk API calls.
Keep closure evidence with patches, retests, log review, token rotation, data-scope decision, customer notice decision, and next audit date.
What buyers should do next
Buyer FAQs
What is CVE-2026-6875?
CVE-2026-6875 is a critical ServiceNow AI Platform sandbox-escape remote code execution vulnerability. Tenable describes it as enabling unauthenticated code execution within the platform in certain circumstances.
Why does this matter to support operations?
ServiceNow-style workflow platforms often connect tickets, approvals, customer records, ITSM actions, AI workflows, and integrations. A patch gate should include workflow blast radius and integration access, not only version status.
What proof should CRM and support buyers request?
Ask for instance inventory, patch or mitigation proof, release family, workflow blast-radius review, connected-app and token review, log searches, customer-data scope, and closure evidence.