Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows.
Cybersecurity company Searchlight Cyber, which found this critical vulnerability and reported it on April 1st, says that it allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks.
ServiceNow addressed the flaw across hosted instances and released CVE-2026-6875 security updates for self-hosted instances one week ago, on July 13th.
Over the weekend, Defused security researchers confirmed that attackers have begun exploiting the vulnerability in the wild, with the first attempts being observed on Friday, days after ServiceNow issued patches.
"We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875)," Defused warned in a Saturday tweet.
"The payloads hit the same pre-auth sink @SLCyberSec documented (/assessment_thanks.do), but the sandbox-escape gadget reaches the same code-execution primitive by a different route than their published PoC."
CVE-2026-6875 exploitation (Defused)
ServiceNow has yet to flag this security as actively abused and, in the official advisory, still states that it is "not currently aware of exploitation against ServiceNow instances."
However, the company advises all customers who have not already done so to secure their systems against attacks by upgrading to a patched release as soon as possible.
... continue reading