Security

ServiceNow AI Platform Flaw Under Active Exploitation

CVE-2026-6875 allows unauthenticated attackers to execute arbitrary code and fully compromise instances.

Omega Editorial· July 21, 2026· 3 min read

Active attacks target critical ServiceNow vulnerability

Threat actors are actively exploiting a critical vulnerability in ServiceNow's AI Platform that allows unauthenticated attackers to execute arbitrary code and completely compromise affected instances.

Defused Cyber reported observing in-the-wild exploitation of CVE-2026-6875, a sandbox escape vulnerability carrying a CVSS score of 9.5. The flaw enables attackers to break out of restricted execution environments and run malicious code without authentication.

Patches available across multiple versions

ServiceNow released patches throughout June 2026 for affected versions. Organizations running the following releases should verify they have applied updates:

  • Brazil EA and Brazil GA
  • Australia Patch 2
  • Zurich Patch 7b and Zurich Patch 9
  • Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13

Searchlight Cyber, which originally reported the vulnerability to ServiceNow on April 1, 2026, provided additional technical details showing the severity of the issue. According to the security firm, successful exploitation allows complete compromise not only of the ServiceNow instance itself but also of all connected proxy servers.

Attack patterns and technical details

Defused Cyber initially observed exploitation attempts targeting a pre-authentication endpoint at "/assessment_thanks.do" using HTTP POST requests. The firm later issued a correction clarifying that the captured attack payload matched the proof-of-concept exploit published by Searchlight Cyber.

The vulnerability represents a sandbox escape, meaning attackers can bypass security controls designed to isolate and restrict code execution. This type of flaw is particularly dangerous because it undermines fundamental security boundaries.

In response to the vulnerability, ServiceNow is implementing broader security enhancements beyond the immediate patch. Security researcher Adam Kues noted the company is "severely restricting the type of code that can run in sandbox contexts" to strengthen instance security going forward.

Why it matters

ServiceNow platforms are widely deployed across enterprises for IT service management, workflow automation, and increasingly AI-powered business processes. A vulnerability that allows complete instance compromise without authentication represents a significant risk to organizations' operational infrastructure and sensitive data. The combination of critical severity, active exploitation, and the availability of public proof-of-concept code creates an urgent patching imperative for self-hosted deployments.

Immediate action required

Organizations running self-hosted ServiceNow instances should immediately verify patch status and apply available fixes if they haven't already done so. The active exploitation combined with public technical details significantly increases risk for unpatched systems.

These details were first reported by The Hacker News, with technical analysis contributed by Defused Cyber and Searchlight Cyber.

#servicenow#vulnerability#cve-2026-6875#sandbox escape#active exploitation#enterprise security

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 2 min read

Suno AI Music Generator Breach Exposed 55M Users' Data

The November 2025 cyberattack stole names, addresses, payment details, and source code revealing alleged mass scraping of copyrighted music.

Via AI Watch · Jul 21, 2026
Security· 3 min read

Cisco Releases Antares: Open-Weight AI Models for Code Vulnerability Detection

The 350M and 1B parameter models run locally to pinpoint security flaws in source code without cloud transmission.

Via AI Watch · Jul 21, 2026
Security· 2 min read

Chinese Police Built AI Tools to Infiltrate Dark Web Content

Law enforcement researchers developed specialized systems to bypass encryption, collect data, and classify Chinese-language material on anonymous networks.

Via AI Watch · Jul 21, 2026