A significant remote code execution vulnerability has been identified and is reportedly being exploited within the ServiceNow AI platform shortly after a patch was released.
Details of the ServiceNow Security Flaw
The vulnerability, designated as CVE-2026-6875, involves a sandbox escape issue. This flaw allows an attacker, without authentication, to execute arbitrary code under specific conditions. ServiceNow implemented a security update on July 14 to address this issue for its hosted instances, while customers managing their own hosting environments need to apply the patch manually.
Cybersecurity Firms’ Role in the Vulnerability’s Exploitation
On the day of the patch release, Searchlight Cyber provided technical insights and demonstrated how the vulnerability could be exploited. Subsequently, on July 18, Defused, a threat intelligence company, reported observing exploitation in the wild, utilizing the information shared by Searchlight Cyber.
Initially, Defused noted a variation in the exploitation method compared to Searchlight’s proof-of-concept. However, they later corrected this statement, confirming that the observed payload matched Searchlight Cyber’s technique.
ServiceNow’s Response and Current Situation
ServiceNow initially claimed no knowledge of active exploitation. However, a spokesperson clarified to SecurityWeek that, although a cybersecurity company reported exploitation activities linked to CVE-2026-6875, these have not been associated with ServiceNow-hosted instances. The company continues to urge both self-hosted and ServiceNow-hosted clients to apply the available patches.
There are currently no additional reports of CVE-2026-6875 being exploited, and it is speculated that such activities might be conducted by cybersecurity researchers rather than malicious actors.
Future Implications and Recommendations
While vulnerabilities within ServiceNow are not frequently targeted by attackers, the potential risk remains significant. The CISA KEV catalog lists only two other flaws patched in 2024. It is crucial for organizations using ServiceNow to remain vigilant and ensure all patches are applied promptly to safeguard against potential threats.
