Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical ServiceNow RCE Vulnerability Addressed

Critical ServiceNow RCE Vulnerability Addressed

Posted on July 20, 2026 By CWS

ServiceNow has issued crucial security patches to mitigate a significant vulnerability in its artificial intelligence platform. This action follows the publication of a proof of concept by researchers, demonstrating how the flaw could be exploited to execute remote code without prior authentication.

Details of the Vulnerability

The vulnerability, identified as CVE-2026-6875, involves a sandbox escape that allows attackers to execute code within susceptible ServiceNow instances. The flaw was highlighted in a technical report by Searchlight Cyber’s Assetnote team, titled “Smashing the ServiceNow Sandbox: Pre-Authentication RCE.”

According to the researchers, exploiting the vulnerability could lead to a complete breach of a ServiceNow instance. This includes unauthorized access to stored data, the creation of administrative accounts, and command execution on connected MID Server proxy systems.

ServiceNow’s Response

ServiceNow acknowledged the vulnerability in advisory KB3137947, dated July 13, 2026, confirming its impact on the ServiceNow AI platform. The company has implemented protections for hosted instances and distributed updates to self-hosted customers and partners. At present, no active exploitation has been detected in the wild.

The public proof of concept exploits the GlideRecord query API of the platform, which is integral to data retrieval and processing within ServiceNow applications. Researchers found certain application paths that processed user inputs in ways that could lead to unauthorized code execution.

Exploitation Techniques and Mitigation

Although ServiceNow employs a restricted script sandbox to block unsafe operations, Assetnote discovered a method to circumvent these restrictions via the platform’s script-include mechanism. The researchers identified that the gs.include() function allowed script libraries to be executed in a less restrictive environment.

By altering global JavaScript objects and properties, attackers could execute code beyond the sandbox’s limitations. This method permitted access to database functions, administrative capabilities, and interactions with MID Servers, which connect cloud instances with internal systems, potentially amplifying the impact of a breach.

The vulnerability was reported to ServiceNow on April 1, 2026. Within 24 hours, the company implemented an initial cloud-side mitigation by blocking modifications to critical JavaScript functions. Subsequent updates addressed the sandbox’s inherent weaknesses, and new Guarded Script protections were introduced to limit the scope of potential attacks.

ServiceNow has resolved CVE-2026-6875 in several patches, including Brazil EA and GA, Australia Patch 2, Zurich Patch 7b and 9, and Yokohama Patch 12 Hot Fix 1b and Patch 13. Customers are urged to ensure their instances are updated and to review any incompatible scripts following these upgrades.

Strengthen your security operations center by enhancing threat detection and enabling rapid investigations. Integrate ANY.RUN with your SOC today.

Cyber Security News Tags:Assetnote, CVE-2026-6875, Cybersecurity, Patch, RCE, sandbox escape, Searchlight Cyber, security updates, ServiceNow, Vulnerability

Post navigation

Previous Post: Capital One Releases AI Security Tool ‘VulnHunter’
Next Post: Hacker Uses AI to Manage Botnet in Dental Clinics

Related Posts

Hackers Target Developers with Fake Job Interviews Hackers Target Developers with Fake Job Interviews Cyber Security News
Vidar Malware Exploits Browser Data and Crypto Wallets Vidar Malware Exploits Browser Data and Crypto Wallets Cyber Security News
Critical FortiSIEM Vulnerability Enable Full RCE and Root Compromise Critical FortiSIEM Vulnerability Enable Full RCE and Root Compromise Cyber Security News
Researchers Details Masking Malicious Scripts and Bypass Defense Mechanisms Researchers Details Masking Malicious Scripts and Bypass Defense Mechanisms Cyber Security News
Debian 13.6 Update: Security Enhancements and Critical Fixes Debian 13.6 Update: Security Enhancements and Critical Fixes Cyber Security News
New Eleven11bot Hacked 86,000 IP Cameras for Massive DDoS Attack New Eleven11bot Hacked 86,000 IP Cameras for Massive DDoS Attack Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft to End Copilot Podcasts in 2026
  • Empirical Secures $25M for AI Cybersecurity Expansion
  • Android AI Agents Vulnerable to Covert Code Execution
  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft to End Copilot Podcasts in 2026
  • Empirical Secures $25M for AI Cybersecurity Expansion
  • Android AI Agents Vulnerable to Covert Code Execution
  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark