Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
ServiceNow AI platform RCE vulnerability CVE-2026-6875 exploited in wild days after patch disclosure.
Summary
A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow's AI platform, described as a sandbox escape, is being exploited in the wild following public disclosure of technical details by Searchlight Cyber on July 14. Threat intelligence firm Defused reported in-the-wild exploitation on July 18, though ServiceNow states no evidence suggests hosted instances are affected and encourages customers to apply patches. The exploitation activity may originate from security researchers rather than threat actors, and ServiceNow has not updated its advisory to reflect the confirmed in-the-wild attacks.
Full text
A critical remote code execution vulnerability that was recently patched in the ServiceNow AI platform is reportedly being exploited in the wild. The security hole is tracked as CVE-2026-6875 and it has been described as a sandbox escape issue that an unauthenticated attacker can exploit in certain circumstances to execute arbitrary code. When it announced the availability of patches on July 14, ServiceNow said a security update addressing the vulnerability had been deployed to hosted instances. However, self-hosted customers have to install the patches themselves. On the same day, cybersecurity firm Searchlight Cyber disclosed technical details and showed how the vulnerability can be exploited. Threat intelligence firm Defused reported on July 18 that it had seen in-the-wild exploitation of CVE-2026-6875, leveraging information Searchlight Cyber had released. Defused initially said the exploit reached the same outcome as Searchlight’s proof-of-concept but through a slightly different method. On Monday, however, the firm issued a correction, saying that closer analysis showed the captured payload was in fact identical to Searchlight Cyber’s own.Advertisement. Scroll to continue reading. The vendor’s initial advisory stated it had no knowledge of active exploitation, and as of this writing, that advisory has not been updated to reflect otherwise. “ServiceNow is aware of a cybersecurity company’s recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as CVE-2026-6875,” a ServiceNow spokesperson told SecurityWeek. “Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts.” “We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so. In addition, we will continue to work directly with customers who need assistance in applying the patches,” the spokesperson added. There do not appear to be any other reports describing the exploitation of CVE-2026-6875, and there is a chance that the activity is being carried out by members of the cybersecurity industry seeking vulnerable systems. ServiceNow informed customers last month of an exploited vulnerability, but the company later clarified that the exploitation had been attributed to security researchers rather than attackers. ServiceNow vulnerabilities are not often exploited by threat actors. CISA’s KEV catalog currently includes only two flaws, both patched in 2024. Related: SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild Related: Fresh SharePoint Vulnerability Exploited Soon After Disclosure Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs WP2Shell WordPress Vulnerabilities Exploited in the WildTwo Scattered Spider Hackers Sentenced to Jail in UK‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process KillingChina’s Top Cybersecurity Firms Hit by Mounting Military Procurement BansTrend Micro, Tanium, ESET and Tenable Patch Severe Product VulnerabilitiesUS Charges Russian Individuals and Firms for Running Cybercrime ServicesWhite House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination InitiativeICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell Latest News Clover Health Investments Discloses Data BreachZimbra Update Patches Critical VulnerabilitiesNeo Emerges From Stealth With $100M to Control and Secure Enterprise AI SoftwareSonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before PatchOpenSSL Silently Fixes ‘HollowByte’ DoS VulnerabilityNew Index Tracks Material Breaches — And Refuses to Add Up the LossesErnst & Young Data Breach Affects Personal, Financial InformationWatch on Demand: Cloud & Data Security Summit Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveJazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.AJ Shipley has been appointed Chief Product Officer at CrowdStrike.Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product.More People On The MoveExpert Insights Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) The AI Token Costs That Can Break Cybersecurity As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-6875