ServiceNow AI Platform Flaw Under Active Exploitation
CVE-2026-6875 allows unauthenticated attackers to execute arbitrary code and fully compromise instances.

Active attacks target critical ServiceNow vulnerability
Threat actors are actively exploiting a critical vulnerability in ServiceNow's AI Platform that allows unauthenticated attackers to execute arbitrary code and completely compromise affected instances.
Defused Cyber reported observing in-the-wild exploitation of CVE-2026-6875, a sandbox escape vulnerability carrying a CVSS score of 9.5. The flaw enables attackers to break out of restricted execution environments and run malicious code without authentication.
Patches available across multiple versions
ServiceNow released patches throughout June 2026 for affected versions. Organizations running the following releases should verify they have applied updates:
- Brazil EA and Brazil GA
- Australia Patch 2
- Zurich Patch 7b and Zurich Patch 9
- Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13
Searchlight Cyber, which originally reported the vulnerability to ServiceNow on April 1, 2026, provided additional technical details showing the severity of the issue. According to the security firm, successful exploitation allows complete compromise not only of the ServiceNow instance itself but also of all connected proxy servers.
Attack patterns and technical details
Defused Cyber initially observed exploitation attempts targeting a pre-authentication endpoint at "/assessment_thanks.do" using HTTP POST requests. The firm later issued a correction clarifying that the captured attack payload matched the proof-of-concept exploit published by Searchlight Cyber.
The vulnerability represents a sandbox escape, meaning attackers can bypass security controls designed to isolate and restrict code execution. This type of flaw is particularly dangerous because it undermines fundamental security boundaries.
In response to the vulnerability, ServiceNow is implementing broader security enhancements beyond the immediate patch. Security researcher Adam Kues noted the company is "severely restricting the type of code that can run in sandbox contexts" to strengthen instance security going forward.
Why it matters
ServiceNow platforms are widely deployed across enterprises for IT service management, workflow automation, and increasingly AI-powered business processes. A vulnerability that allows complete instance compromise without authentication represents a significant risk to organizations' operational infrastructure and sensitive data. The combination of critical severity, active exploitation, and the availability of public proof-of-concept code creates an urgent patching imperative for self-hosted deployments.
Immediate action required
Organizations running self-hosted ServiceNow instances should immediately verify patch status and apply available fixes if they haven't already done so. The active exploitation combined with public technical details significantly increases risk for unpatched systems.
These details were first reported by The Hacker News, with technical analysis contributed by Defused Cyber and Searchlight Cyber.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call