Critical ServiceNow vulnerability now actively exploited, threatening enterprise AI workflows

2 Sources

Share

Attackers are exploiting CVE-2026-6875, a critical ServiceNow AI Platform flaw that enables unauthenticated remote code execution. Discovered by Searchlight Cyber and reported in April, the sandbox escape vulnerability affects enterprise workflows at 85% of Fortune 500 companies. Defused security researchers detected exploitation attempts just days after patches were released on July 13th.

ServiceNow Vulnerability Enables Unauthenticated Remote Code Execution

A critical ServiceNow code execution flaw is now actively exploited by attackers, threatening enterprise systems worldwide. CVE-2026-6875, rated with a CVSS score of 9.5, represents a severe sandbox escape vulnerability affecting the ServiceNow AI Platform—an enterprise-grade Platform-as-a-Service that helps businesses integrate AI into core enterprise workflows

1

2

. The flaw allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks

1

.

Source: Hacker News

Source: Hacker News

Exploitation Detected Days After Security Patches Released

Searchlight Cyber discovered and reported the ServiceNow AI Platform flaw on April 1st, warning that it allows complete compromise of ServiceNow instances as well as all connected proxy servers

2

. ServiceNow addressed the vulnerability across hosted instances and released security patches for self-hosted versions on July 13th across multiple platform versions including Brazil EA and GA, Australia Patch 2, Zurich Patch 7b and 9, and Yokohama Patch 12 Hot Fix 1b and Patch 13

2

. However, Defused security researchers confirmed exploitation attempts began on Friday, just days after patches became available

1

.

Attack Methods Target Pre-Authentication Endpoint

The exploitation efforts target the same pre-authentication endpoint at /assessment_thanks.do using HTTP POST requests, according to Defused

2

. While attackers hit the same pre-auth sink documented by Searchlight Cyber, the sandbox-escape gadget reaches the same code execution primitive by a different route than the published proof-of-concept exploit. This variation suggests threat actors have developed alternative exploitation methods, potentially making detection more challenging for security teams.

Immediate Action Required for Enterprise Customers

ServiceNow has yet to officially flag this security vulnerability as actively abused and still states in its advisory that it is "not currently aware of exploitation against ServiceNow instances"

1

. Despite this, the company advises all customers who have not already done so to secure their systems by upgrading to patched releases immediately. Beyond deploying fixes, ServiceNow is enhancing instance security by severely restricting the type of code that can run in sandbox contexts, according to security researcher Adam Kues

2

. Given that the AI Platform runs more than 100 billion workflows annually and powers over 100,000 enterprise AI apps at 85% of Fortune 500 companies, the potential impact of successful exploitation is substantial

1

.

Source: BleepingComputer

Source: BleepingComputer

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved