Threat actors are actively exploiting a critical vulnerability in the ServiceNow AI Platform, as reported by Defused Cyber. This significant security issue, identified as CVE-2026-6875 with a CVSS score of 9.5, involves a sandbox escape flaw that permits unauthenticated code execution.
Patching Efforts and Vulnerability Details
The vulnerability has been addressed through patches released by ServiceNow in June. These updates were applied to specific versions, including Brazil EA and GA, Australia Patch 2, Zurich Patch 7b and 9, and Yokohama Patch 12 Hot Fix 1b and Patch 13. Searchlight Cyber, who initially disclosed the vulnerability details on April 1, 2026, highlighted the potential for complete system compromise, including all connected proxy servers.
Security Enhancements and Exploitation Tactics
In response to this threat, ServiceNow is intensifying security measures by significantly limiting the types of code executable within sandbox environments, as noted by security researcher Adam Kues. Despite these efforts, Defused Cyber has observed ongoing attempts to exploit the same pre-authentication endpoint through HTTP POST requests, using different methods outlined in a proof-of-concept exploit.
Recommendations for Users
Given the current exploitation activities, it is imperative for users of self-hosted ServiceNow versions to implement the provided patches if they have not done so already. This action is crucial to mitigate potential risks and safeguard their systems from unauthorized code execution.
As the situation evolves, it is essential for organizations to stay vigilant and ensure their systems are up-to-date with the latest security patches. Continuous monitoring and proactive security strategies will be key to defending against such vulnerabilities in the future.
