CVE-2026-6875

Published Jul 13, 2026

Last updated 11 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-6875 is a code injection vulnerability found in the ServiceNow AI Platform, which is a Platform-as-a-Service used for building and automating digital workflows. This flaw allows unauthenticated attackers to bypass ServiceNow's script sandbox and execute code remotely on a targeted instance. The vulnerability was discovered by Searchlight Cyber researchers, who reported it to ServiceNow in early April 2026. ServiceNow deployed security updates to hosted instances and made patches available to self-hosted customers and partners throughout June 2026, with the public disclosure of the vulnerability occurring on July 13, 2026. Reports of active exploitation in the wild began around July 18-19, 2026, targeting the `/assessment_thanks.do` endpoint.

Description
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Source
psirt@servicenow.com
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.5
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-94

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. 🔒 #CyberSecurity CVE-2026-6875: Detecting and Patching ServiceNow AI Platform Sandbox Escape "Defenders need to mobilize immediately. A critical vulnerability, tracked as CVE-2026-6875, has…" 🔗 https://t.co/G8Hr56Sd5T #CyberSecurity #ThreatIntel #critical #zeroday #cv

    @SecurityAr58409

    23 Jul 2026

    81 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🛑 ServiceNow CVE-2026-6875 turns AI workflow platforms into urgent patch… CVE-2026-6875 is a critical ServiceNow AI Platform sandbox escape with reported exploitatio… 🔗 Details → https://t.co/nntx3MGvOp

    @lucasverdan

    22 Jul 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-2026-6875: Sandbox Escape in ServiceNow AI Platform Critical Vulnerability Alert! ServiceNow is affected by CVE-2026-6875. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/GxRgw3Gx4r 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-

    @zoomeye_team

    22 Jul 2026

    1780 Impressions

    9 Retweets

    14 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  4. Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875: Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical… https://t.co/BEQFDZJ69y ht

    @shah_sheikh

    21 Jul 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. It's Already When. — Field Note ServiceNow CVE-2026-6875 and WordPress WP2Shell flaws are under active exploitation, while a critical unauthenticated NGINX RCE (CVE-2026-42... https://t.co/We8w4X7y6z #CyberSecurity #BlueTeam https://t.co/BceM5tJLEf

    @itsalreadywhen

    20 Jul 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ServiceNowのサンドボックスエスケープCVE-2026-6875が悪用されている。ハニポ運用業のDefusedCyber社報告。 PoC(攻撃の概念実証コード)も公開済み。 https://t.co/j3WGKfOEo4

    @__kokumoto

    19 Jul 2026

    1534 Impressions

    2 Retweets

    13 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  7. 🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-6875](https://t.co/vawnA2dlvy) S... https://t.co/vawnA2dlvy #Vulnerability #CVE #ZeroDay

    @MalwareObserver

    13 Jul 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes