A critical vulnerability in the ServiceNow AI Platform (CVE-2026-6875) is now being actively exploited, with attacks confirmed over the weekend. The flaw lets an unauthenticated attacker escape the platform’s sandbox and execute code remotely — no login required.
Who’s affected: Any organisation running a self-hosted ServiceNow instance that hasn’t applied the 13 July patch. ServiceNow says it has already patched hosted instances, but self-hosted deployments need to act now. ServiceNow powers workflows at 85% of Fortune 500 companies and processes over 100 billion enterprise workflows per year.
Why it matters even if you don’t run ServiceNow: Most Australian SMBs don’t run ServiceNow directly, but your IT provider, accountant, insurer, or bank almost certainly does. In our managed client environments, we regularly see ServiceNow sitting behind the scenes — particularly in financial services and professional services firms — handling ticketing, compliance workflows, and vendor management. A compromised ServiceNow instance at one of your suppliers means your data could be exposed through no fault of your own. This is exactly the kind of third-party platform risk that a proper vendor risk assessment is designed to catch.
What to do:
- If you self-host ServiceNow, apply the July 13 security update immediately.
- If you rely on a vendor that uses ServiceNow, ask them whether they’ve patched.
- Review your critical vendor list and confirm each one has a process for applying security updates within 48 hours of release.
If you’re not sure what platforms your vendors are running, talk to All IT about a vendor risk review.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
