ServiceNow AI Platform CVE-2026-6875 Actively Exploited

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Defused Cyber reports observing active in-the-wild exploitation of CVE-2026-6875, a critical sandbox escape vulnerability in ServiceNow AI Platform with a CVSS score of 9.5 that allows unauthenticated remote code execution.
- ServiceNow released patches throughout June for Brazil EA, Brazil GA, Australia Patch 2, Zurich Patch 7b and Patch 9, Yokohama Patch 12 Hot Fix 1b, and Yokohama Patch 13, and is 'enhancing instance security by severely restricting the type of code that can run in sandbox contexts,' per security researcher Adam Kues.
- Searchlight Cyber, which disclosed additional technical specifics and reported the issue to ServiceNow on April 1, 2026, says the flaw enables complete compromise of the ServiceNow instance and all connected proxy servers.
- Defused Cyber initially said attackers were targeting the pre-authentication '/assessment_thanks.do' endpoint via HTTP POST requests, then issued a correction confirming the captured payload actually matches Searchlight Cyber's published proof-of-concept exploit.
- ServiceNow publicly disputes the exploitation claim, telling The Hacker News that based on its investigation it has 'not observed evidence that this activity is related to instances that ServiceNow hosts.'
Why it matters: A CVSS 9.5 pre-authentication RCE on an enterprise platform puts every unpatched self-hosted ServiceNow customer at immediate risk of full instance and proxy-server takeover — but ServiceNow's flat denial that any of the observed activity touches its hosted instances creates a factual gap that defenders and incident-response teams will have to reconcile before attributing any compromise.




