ServiceNow AI Platform RCE Flaw Exploited Days After Patch
TL;DR
- CVE-2026-6875 is a sandbox escape in the ServiceNow AI Platform that an unauthenticated attacker can use to execute arbitrary code.
- ServiceNow deployed the fix to hosted instances on July 14, 2026, the same day Searchlight Cyber disclosed technical details and a proof-of-concept.
- Threat intelligence firm Defused reported in-the-wild exploitation on July 18, four days after the patch and the public PoC.
The gap between a vulnerability being patched and being exploited in the wild used to be measured in months. In this case it was four days.
SecurityWeek reported that CVE-2026-6875, a sandbox escape in the ServiceNow AI Platform, is now under active exploitation. ServiceNow deployed a fix to hosted instances on July 14, 2026. On the same day, the cybersecurity firm Searchlight Cyber disclosed technical details and showed how the vulnerability can be exploited. Four days later, threat intelligence firm Defused reported it had seen the flaw exploited in the wild.
The vulnerability itself is the kind of finding a security team dreads. It is described as a sandbox escape that an unauthenticated attacker can exploit to execute arbitrary code. No credentials required. The path from public PoC to captured payload was so short that Defused initially thought the attacker had built a variant, and later corrected the record when a closer look showed the payload was identical to Searchlight Cyber's own.
ServiceNow's carefully worded response is that it has not observed evidence the activity is related to instances the company hosts. That is a specific claim about hosted customers, which is exactly the population ServiceNow already patched on July 14. The exposed population is the self-hosted one, where administrators have to install the update themselves and where there is no vendor-side view into whether they have.
The honest caveat is that this is still one observation from one threat intel source. There do not appear to be any other public reports of exploitation as of publication. What the reporting does not give you is a count of vulnerable instances, a description of what attackers are actually doing after they land, or any attribution to a known crew.
The forward-looking piece is who benefits from moving fast. Any self-hosted ServiceNow AI Platform customer that gets the patch on this week has bought themselves out of the window where a copy-pasted PoC is the primary threat model. The ones that do not are betting the exploit does not spread, and the last four days are not encouraging on that bet.
Originally reported by securityweek.com
Read the original article →Original headline: Critical ServiceNow AI Platform Sandbox-Escape RCE (CVE-2026-6875) Under Active Exploitation