• 2 min read
ServiceNow RCE flaw is now under active attack
Attackers are exploiting critical ServiceNow bug CVE-2026-6875 days after patches shipped. The flaw enables pre-auth remote code execution.

Image: BleepingComputer
Attackers have started exploiting CVE-2026-6875, a critical flaw in the ServiceNow AI Platform, according to threat intelligence firm Defused. The bug was discovered by Searchlight Cyber, which reported it on April 1st and said it could let unauthenticated attackers escape the sandbox and achieve remote code execution on the platform in high-complexity attacks.
ServiceNow patched the issue on its hosted instances and released security updates for self-hosted deployments on July 13th, one week ago. Over the weekend, Defused said it confirmed active exploitation in the wild, with the first attempts seen on Friday, only days after patches became available.
“We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875).” “The payloads hit the same pre-auth sink @SLCyberSec documented (/assessment_thanks.do), but the sandbox-escape gadget reaches the same code-execution primitive by a different route than their published PoC.”
ServiceNow has not yet updated its advisory to mark the vulnerability as actively exploited. The company still says it is “not currently aware of exploitation against ServiceNow instances,” while urging customers that have not already done so to upgrade to a patched release immediately.

Recommended reading
Hugging Face hit by AI agents, then blocked by LLM guardrails
A ServiceNow spokesperson did not immediately respond when BleepingComputer asked for comment on Defused’s findings.
The disclosure follows another recent ServiceNow security issue. Last month, the company privately disclosed an incident in which attackers queried data from customer instances through an unauthenticated access flaw in a vulnerable API endpoint. ServiceNow later said that activity was tied to security researchers or customer-led research associated with bug bounty submissions, not malicious threat actors.
ServiceNow says its AI Platform runs more than 100 billion workflows each year and supports over 100,000 enterprise AI apps at 85% of Fortune 500 companies.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via BleepingComputer


