2 Sources
[1]
Critical ServiceNow code execution flaw now exploited in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate
[2]
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape
Share
Copy Link
Attackers are exploiting CVE-2026-6875, a critical ServiceNow AI Platform flaw that enables unauthenticated remote code execution. Discovered by Searchlight Cyber and reported in April, the sandbox escape vulnerability affects enterprise workflows at 85% of Fortune 500 companies. Defused security researchers detected exploitation attempts just days after patches were released on July 13th.
A critical ServiceNow code execution flaw is now actively exploited by attackers, threatening enterprise systems worldwide. CVE-2026-6875, rated with a CVSS score of 9.5, represents a severe sandbox escape vulnerability affecting the ServiceNow AI Platform—an enterprise-grade Platform-as-a-Service that helps businesses integrate AI into core enterprise workflows
1
2
. The flaw allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks1
.
Source: Hacker News
Searchlight Cyber discovered and reported the ServiceNow AI Platform flaw on April 1st, warning that it allows complete compromise of ServiceNow instances as well as all connected proxy servers
2
. ServiceNow addressed the vulnerability across hosted instances and released security patches for self-hosted versions on July 13th across multiple platform versions including Brazil EA and GA, Australia Patch 2, Zurich Patch 7b and 9, and Yokohama Patch 12 Hot Fix 1b and Patch 132
. However, Defused security researchers confirmed exploitation attempts began on Friday, just days after patches became available1
.The exploitation efforts target the same pre-authentication endpoint at /assessment_thanks.do using HTTP POST requests, according to Defused
2
. While attackers hit the same pre-auth sink documented by Searchlight Cyber, the sandbox-escape gadget reaches the same code execution primitive by a different route than the published proof-of-concept exploit. This variation suggests threat actors have developed alternative exploitation methods, potentially making detection more challenging for security teams.Related Stories
ServiceNow has yet to officially flag this security vulnerability as actively abused and still states in its advisory that it is "not currently aware of exploitation against ServiceNow instances"
1
. Despite this, the company advises all customers who have not already done so to secure their systems by upgrading to patched releases immediately. Beyond deploying fixes, ServiceNow is enhancing instance security by severely restricting the type of code that can run in sandbox contexts, according to security researcher Adam Kues2
. Given that the AI Platform runs more than 100 billion workflows annually and powers over 100,000 enterprise AI apps at 85% of Fortune 500 companies, the potential impact of successful exploitation is substantial1
.
Source: BleepingComputer
Summarized by
Navi
[1]
07 Apr 2026•Technology

30 Jun 2026•Technology

10 Jun 2026•Technology

1
Policy and Regulation

2
Technology

3
Policy and Regulation
