AI description
CVE-2026-6875 is a code injection vulnerability found in the ServiceNow AI Platform, which is a Platform-as-a-Service used for building and automating digital workflows. This flaw allows unauthenticated attackers to bypass ServiceNow's script sandbox and execute code remotely on a targeted instance. The vulnerability was discovered by Searchlight Cyber researchers, who reported it to ServiceNow in early April 2026. ServiceNow deployed security updates to hosted instances and made patches available to self-hosted customers and partners throughout June 2026, with the public disclosure of the vulnerability occurring on July 13, 2026. Reports of active exploitation in the wild began around July 18-19, 2026, targeting the `/assessment_thanks.do` endpoint.
- Description
- ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
- Source
- psirt@servicenow.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 9.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-94
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
1
🔒 #CyberSecurity CVE-2026-6875: Detecting and Patching ServiceNow AI Platform Sandbox Escape "Defenders need to mobilize immediately. A critical vulnerability, tracked as CVE-2026-6875, has…" 🔗 https://t.co/G8Hr56Sd5T #CyberSecurity #ThreatIntel #critical #zeroday #cv
@SecurityAr58409
23 Jul 2026
81 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛑 ServiceNow CVE-2026-6875 turns AI workflow platforms into urgent patch… CVE-2026-6875 is a critical ServiceNow AI Platform sandbox escape with reported exploitatio… 🔗 Details → https://t.co/nntx3MGvOp
@lucasverdan
22 Jul 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-6875: Sandbox Escape in ServiceNow AI Platform Critical Vulnerability Alert! ServiceNow is affected by CVE-2026-6875. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/GxRgw3Gx4r 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-
@zoomeye_team
22 Jul 2026
1780 Impressions
9 Retweets
14 Likes
6 Bookmarks
0 Replies
0 Quotes
Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875: Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical… https://t.co/BEQFDZJ69y ht
@shah_sheikh
21 Jul 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
It's Already When. — Field Note ServiceNow CVE-2026-6875 and WordPress WP2Shell flaws are under active exploitation, while a critical unauthenticated NGINX RCE (CVE-2026-42... https://t.co/We8w4X7y6z #CyberSecurity #BlueTeam https://t.co/BceM5tJLEf
@itsalreadywhen
20 Jul 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ServiceNowのサンドボックスエスケープCVE-2026-6875が悪用されている。ハニポ運用業のDefusedCyber社報告。 PoC(攻撃の概念実証コード)も公開済み。 https://t.co/j3WGKfOEo4
@__kokumoto
19 Jul 2026
1534 Impressions
2 Retweets
13 Likes
5 Bookmarks
0 Replies
0 Quotes
🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-6875](https://t.co/vawnA2dlvy) S... https://t.co/vawnA2dlvy #Vulnerability #CVE #ZeroDay
@MalwareObserver
13 Jul 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes