Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical ServiceNow RCE Vulnerability Addressed

Critical ServiceNow RCE Vulnerability Addressed

Posted on July 20, 2026 By CWS

ServiceNow has issued crucial security patches to mitigate a significant vulnerability in its artificial intelligence platform. This action follows the publication of a proof of concept by researchers, demonstrating how the flaw could be exploited to execute remote code without prior authentication.

Details of the Vulnerability

The vulnerability, identified as CVE-2026-6875, involves a sandbox escape that allows attackers to execute code within susceptible ServiceNow instances. The flaw was highlighted in a technical report by Searchlight Cyber’s Assetnote team, titled “Smashing the ServiceNow Sandbox: Pre-Authentication RCE.”

According to the researchers, exploiting the vulnerability could lead to a complete breach of a ServiceNow instance. This includes unauthorized access to stored data, the creation of administrative accounts, and command execution on connected MID Server proxy systems.

ServiceNow’s Response

ServiceNow acknowledged the vulnerability in advisory KB3137947, dated July 13, 2026, confirming its impact on the ServiceNow AI platform. The company has implemented protections for hosted instances and distributed updates to self-hosted customers and partners. At present, no active exploitation has been detected in the wild.

The public proof of concept exploits the GlideRecord query API of the platform, which is integral to data retrieval and processing within ServiceNow applications. Researchers found certain application paths that processed user inputs in ways that could lead to unauthorized code execution.

Exploitation Techniques and Mitigation

Although ServiceNow employs a restricted script sandbox to block unsafe operations, Assetnote discovered a method to circumvent these restrictions via the platform’s script-include mechanism. The researchers identified that the gs.include() function allowed script libraries to be executed in a less restrictive environment.

By altering global JavaScript objects and properties, attackers could execute code beyond the sandbox’s limitations. This method permitted access to database functions, administrative capabilities, and interactions with MID Servers, which connect cloud instances with internal systems, potentially amplifying the impact of a breach.

The vulnerability was reported to ServiceNow on April 1, 2026. Within 24 hours, the company implemented an initial cloud-side mitigation by blocking modifications to critical JavaScript functions. Subsequent updates addressed the sandbox’s inherent weaknesses, and new Guarded Script protections were introduced to limit the scope of potential attacks.

ServiceNow has resolved CVE-2026-6875 in several patches, including Brazil EA and GA, Australia Patch 2, Zurich Patch 7b and 9, and Yokohama Patch 12 Hot Fix 1b and Patch 13. Customers are urged to ensure their instances are updated and to review any incompatible scripts following these upgrades.

Strengthen your security operations center by enhancing threat detection and enabling rapid investigations. Integrate ANY.RUN with your SOC today.

Cyber Security News Tags:Assetnote, CVE-2026-6875, Cybersecurity, Patch, RCE, sandbox escape, Searchlight Cyber, security updates, ServiceNow, Vulnerability

Post navigation

Previous Post: Capital One Releases AI Security Tool ‘VulnHunter’
Next Post: Hacker Uses AI to Manage Botnet in Dental Clinics

Related Posts

Cisco AnyConnect VPN Server Vulnerability Let Attackers Trigger DoS Attack Cisco AnyConnect VPN Server Vulnerability Let Attackers Trigger DoS Attack Cyber Security News
Microsoft Exchange Server Vulnerability Enables Privelege Escalation Microsoft Exchange Server Vulnerability Enables Privelege Escalation Cyber Security News
Critical FreePBX Flaw Exposes User Portals Critical FreePBX Flaw Exposes User Portals Cyber Security News
Apple Warns Of Series Mercenary Spyware Attacks Targeting Users Devices Apple Warns Of Series Mercenary Spyware Attacks Targeting Users Devices Cyber Security News
CISA Warns of Apple macOS, iOS, tvOS, Safari, and watchOS Vulnerability Exploited in Attacks CISA Warns of Apple macOS, iOS, tvOS, Safari, and watchOS Vulnerability Exploited in Attacks Cyber Security News
Microsoft Dismantles 300+ Websites Used to Distribute RaccoonO365 Phishing Service Microsoft Dismantles 300+ Websites Used to Distribute RaccoonO365 Phishing Service Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark