VYPR
patchPublished Jul 14, 2026· Updated Jul 26, 2026· 7 sources

Critical ServiceNow Vulnerability Allows Remote Code Execution in AI Platform

ServiceNow has released security updates to address CVE-2026-6875, a critical sandbox escape vulnerability in its AI Platform that allows unauthenticated attackers to execute malicious code remotely.

ServiceNow has disclosed and fixed a critical security vulnerability in its AI Platform that could allow unauthenticated attackers to execute code within affected ServiceNow environments. The flaw, tracked as CVE-2026-6875, is described as a sandbox escape vulnerability and affects both hosted and self-hosted ServiceNow deployments.

ServiceNow stated that the vulnerability could allow an attacker to circumvent intended platform restrictions and execute code in certain circumstances. Because exploitation does not require authentication, the issue poses a significant risk to exposed ServiceNow instances that have not yet received the necessary security updates. Enterprises widely utilize ServiceNow for critical functions such as IT service management, workflow automation, customer operations, security operations, and internal business processes.

A successful remote code execution attack against such a platform could enable attackers to disrupt workflows, access sensitive data, modify records, or leverage the compromised environment as a launchpad for further malicious activities. While ServiceNow has not released extensive technical details regarding the root cause of the vulnerability, the company published an advisory (KB3137947) on July 13, 2026, limiting specifics to allow customers time to patch before exploits become widely available.

ServiceNow has already deployed security updates to its hosted instances and made relevant updates available to self-hosted customers and partners. Organizations managing their own ServiceNow environments are urged to review their current family release and install the appropriate patch or upgrade to a fixed version promptly. The vulnerability is addressed in specific releases, including Brazil Early Access and General Availability, Australia Patch 2, Zurich Patch 7b or 9, and Yokohama Patch 12 Hot Fix 1b or 13.

While ServiceNow has indicated it is not currently aware of any active exploitation of CVE-2026-6875 in the wild, the public disclosure of a critical unauthenticated remote code execution flaw can quickly attract the attention of security researchers and malicious actors. Therefore, organizations should treat this issue with urgency, even in the absence of observed suspicious activity.

Administrators are advised to confirm their ServiceNow instance's hosting environment (hosted by ServiceNow or self-hosted) and verify that platform updates have been applied. For self-hosted environments, reviewing ServiceNow’s security maintenance guidance and patch status is crucial. Security teams should also enhance monitoring for administrative activity, unusual integrations, unexpected workflow modifications, and suspicious API behavior following the update.

The CVE record for CVE-2026-6875 is available on CVE.org, and further patch and maintenance information can be found in ServiceNow advisories KB2930717 and KB2930740. Prompt remediation remains the most effective defense against potential exploitation of this critical vulnerability.

While ServiceNow's official advisory stated no exploitation was known, security researchers at Defused have confirmed active in-the-wild exploitation of CVE-2026-6875. They observed initial attempts on Friday, shortly after patches were released, noting that attackers are using a different route to achieve code execution compared to the proof-of-concept initially documented by Searchlight Cyber.

Threat intelligence firm Defused has confirmed that attackers have begun actively exploiting CVE-2026-6875 in the wild, with exploitation attempts appearing as early as Friday and confirmed over the weekend. While the attackers are targeting the same pre-authentication endpoint (/assessment_thanks.do) as documented by researchers, they are employing a different method to achieve the sandbox escape and remote code execution.

The new article provides additional technical details on the exploitation of CVE-2026-6875, noting that threat actors are targeting the same pre-authentication endpoint ("/assessment_thanks.do") using HTTP POST requests. It also highlights that ServiceNow is enhancing instance security by severely restricting the type of code that can run in sandbox contexts, in addition to releasing patches.

Exploitation of the ServiceNow AI platform vulnerability, CVE-2026-6875, has been observed in the wild just days after its public disclosure and the release of patches. Threat intelligence firm Defused reported seeing exploitation attempts that leveraged technical details shared by Searchlight Cyber, noting that the captured payload was identical to known proof-of-concept methods. While ServiceNow stated they have not observed evidence of exploitation affecting their hosted instances, they are urging all customers to apply the relevant patches.

While the initial advisory from ServiceNow indicated no known exploitation, subsequent telemetry from threat intelligence firm Defused has confirmed that exploit attempts for CVE-2026-6875 began shortly after the vulnerability's public disclosure. This active exploitation in the wild necessitates immediate patching and the enablement of Guarded Script for self-hosted instances to mitigate sandbox escape risks.

The new article from Help Net Security provides a specific CVE identifier, CVE-2026-6875, for the ServiceNow pre-authentication remote code execution vulnerability. It also confirms that attackers have begun actively exploiting this flaw in the wild, highlighting the immediate risk to organizations using the platform. Additionally, the article briefly mentions a breach at Hugging Face, though details remain limited.

Synthesized by Vypr AI