Skip to content
Tech News
← Back to articles

Critical ServiceNow code execution flaw now exploited in attacks

read original more articles
Why This Matters

The exploitation of the critical CVE-2026-6875 vulnerability in ServiceNow's AI Platform highlights the urgent need for organizations to prioritize timely security updates. As attackers actively exploit this flaw in the wild, it underscores the importance of rapid patch deployment to protect enterprise workflows and sensitive data. This incident serves as a reminder of the evolving threat landscape targeting enterprise SaaS platforms and the necessity for proactive cybersecurity measures.

Key Takeaways

Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.

Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows.

Cybersecurity company Searchlight Cyber, which found this critical vulnerability and reported it on April 1st, says that it allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks.

ServiceNow addressed the flaw across hosted instances and released CVE-2026-6875 security updates for self-hosted instances one week ago, on July 13th.

Over the weekend, Defused security researchers confirmed that attackers have begun exploiting the vulnerability in the wild, with the first attempts being observed on Friday, days after ServiceNow issued patches.

"We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875)," Defused warned in a Saturday tweet.

"The payloads hit the same pre-auth sink @SLCyberSec documented (/assessment_thanks.do), but the sandbox-escape gadget reaches the same code-execution primitive by a different route than their published PoC."

CVE-2026-6875 exploitation (Defused)

ServiceNow has yet to flag this security as actively abused and, in the official advisory, still states that it is "not currently aware of exploitation against ServiceNow instances."

However, the company advises all customers who have not already done so to secure their systems against attacks by upgrading to a patched release as soon as possible.

... continue reading