Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ServiceNow AI Platform Security Flaw Under Attack

ServiceNow AI Platform Security Flaw Under Attack

Posted on July 21, 2026 By CWS

Threat actors are actively exploiting a critical vulnerability in the ServiceNow AI Platform, as reported by Defused Cyber. This significant security issue, identified as CVE-2026-6875 with a CVSS score of 9.5, involves a sandbox escape flaw that permits unauthenticated code execution.

Patching Efforts and Vulnerability Details

The vulnerability has been addressed through patches released by ServiceNow in June. These updates were applied to specific versions, including Brazil EA and GA, Australia Patch 2, Zurich Patch 7b and 9, and Yokohama Patch 12 Hot Fix 1b and Patch 13. Searchlight Cyber, who initially disclosed the vulnerability details on April 1, 2026, highlighted the potential for complete system compromise, including all connected proxy servers.

Security Enhancements and Exploitation Tactics

In response to this threat, ServiceNow is intensifying security measures by significantly limiting the types of code executable within sandbox environments, as noted by security researcher Adam Kues. Despite these efforts, Defused Cyber has observed ongoing attempts to exploit the same pre-authentication endpoint through HTTP POST requests, using different methods outlined in a proof-of-concept exploit.

Recommendations for Users

Given the current exploitation activities, it is imperative for users of self-hosted ServiceNow versions to implement the provided patches if they have not done so already. This action is crucial to mitigate potential risks and safeguard their systems from unauthorized code execution.

As the situation evolves, it is essential for organizations to stay vigilant and ensure their systems are up-to-date with the latest security patches. Continuous monitoring and proactive security strategies will be key to defending against such vulnerabilities in the future.

The Hacker News Tags:AI vulnerability, code execution, CVE-2026-6875, Cybersecurity, Defused Cyber, sandbox escape, Searchlight Cyber, security patch, ServiceNow, Threat Actors

Post navigation

Previous Post: ServiceNow Vulnerability Exploited Post-Disclosure
Next Post: Meta Awards $78,000 for Major Support Data Vulnerability

Related Posts

Lazarus Exploits Windows Flaw to Deploy New Backdoor Lazarus Exploits Windows Flaw to Deploy New Backdoor The Hacker News
Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control The Hacker News
Shai-Hulud Expands Credential Scanning to 469 Paths Shai-Hulud Expands Credential Scanning to 469 Paths The Hacker News
CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidence CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidence The Hacker News
Checkmarx Data Breach: GitHub Data Exposed on Dark Web Checkmarx Data Breach: GitHub Data Exposed on Dark Web The Hacker News
Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark