ServiceNow vulnerabilities
1 CVE tracked
ServiceNow appears in recent threat reporting primarily due to active exploitation and a prolonged data theft campaign. A critical sandbox escape vulnerability in the ServiceNow AI Platform, CVE-2026-6875 (CVSS 9.5), is being exploited in the wild for unauthenticated code execution. Concurrently, the 'City-Forum' campaign has been leveraging unauthenticated guest access to exfiltrate data from exposed ServiceNow customer portals since at least March 2025. Defenders must prioritize patching CVE-2026-6875 and immediately review access controls and exposed data on public-facing portals.
Azərbaycanca: ServiceNow, son hesabatlarda kritik təhlükəsizlik riskləri ilə əlaqədar görünür. Əsas hadisə, AI Platform-da aşkar edilmiş CVE-2026-6875 kritik zəifliyidir və bu boşluq hazırda aktiv şəkildə istismar olunur. Bundan əlavə, 'City-Forum' adlı uzunmüddətli kampaniya çərçivəsində ServiceNow müştəri portallarından autentifikasiya olunmamış qonaq girişi vasitəsilə məlumatların oğurlanması müşahidə edilir. Müdafiəçilər dərhal CVE-2026-6875 üçün yamaqları tətbiq etməli və ictimaiyyətə açıq portallarda məruz qalmış məlumatların auditini aparmalıdırlar.
This vendor's CVEs1
This hub is built from skopnix's own reporting on ServiceNow: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.