Exploitation of Critical ServiceNow Vulnerability CVE-2026-6875 Underway, Threat Intelligence Reports

Attackers have begun actively exploiting a critical vulnerability within the ServiceNow AI Platform, identified as CVE-2026-6875. This alarming development comes from threat intelligence firm Defused, which has observed in-the-wild attempts to leverage the flaw shortly after ServiceNow released security patches. The vulnerability, discovered by cybersecurity company Searchlight Cyber, allows unauthenticated threat actors to break out of the platform’s sandbox environment and execute arbitrary code remotely, posing a significant risk to organizations relying on ServiceNow for their enterprise workflows.
Unraveling the ServiceNow Vulnerability: CVE-2026-6875
The ServiceNow AI Platform, formerly known as the Now Platform, is a cornerstone for many large enterprises, offering a robust Platform-as-a-Service (PaaS) solution designed to integrate artificial intelligence capabilities into critical business operations. Its widespread adoption, powering over 100 billion workflows annually and supporting more than 100,000 enterprise AI applications across 85% of Fortune 500 companies, makes any security vulnerability within it a matter of global concern.
The critical nature of CVE-2026-6875 lies in its ability to bypass the platform’s security sandbox. This sandbox mechanism is designed to isolate potentially untrusted code and processes, preventing them from affecting the underlying system or other applications. By successfully escaping this sandbox, attackers gain a significant foothold, enabling them to execute malicious code directly within the ServiceNow environment. This could lead to a wide range of detrimental actions, including data theft, system manipulation, deployment of ransomware, or using the compromised instance as a pivot point for further attacks within an organization’s network.
Searchlight Cyber, the firm that initially identified and reported this critical vulnerability on April 1st, detailed its findings in a comprehensive report. Their research highlighted that the exploitation is possible through "high-complexity attacks," suggesting that sophisticated threat actors are likely to be the primary exploiters, though the potential for less skilled attackers to adapt existing exploits remains a concern. The discovery and disclosure of such a significant flaw underscore the ongoing cat-and-mouse game between cybersecurity researchers and malicious actors, with platforms like ServiceNow constantly under scrutiny.

A Rapid Response and Evolving Threat Landscape
Following the disclosure by Searchlight Cyber, ServiceNow moved swiftly to address the vulnerability. For its hosted instances, the company has implemented fixes. For self-hosted instances, security updates were released on July 13th, corresponding to CVE-2026-6875’s official listing on the National Vulnerability Database (NVD). This rapid patching cycle is crucial in mitigating the risk posed by newly discovered vulnerabilities.
However, the cybersecurity landscape is dynamic, and the window between patch release and active exploitation can be alarmingly small. Just days after ServiceNow issued its security advisories, Defused researchers observed the first attempts at exploiting CVE-2026-6875 in the wild. Their confirmation came via a tweet on a Saturday, stating, "We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875)."
Defused further elaborated that the observed exploitation attempts targeted the same pre-authentication sinkhole identified by Searchlight Cyber, specifically the /assessment_thanks.do endpoint. However, they noted a crucial difference: the attackers were utilizing a distinct "sandbox-escape gadget" to achieve code execution, employing a different route than the one detailed in Searchlight Cyber’s proof-of-concept (PoC). This suggests that attackers are not merely replicating existing PoCs but are developing their own methods, potentially making detection and defense more challenging.
The discrepancy between Defused’s real-time observation of active exploitation and ServiceNow’s official advisory, which stated they were "not currently aware of exploitation against ServiceNow instances," highlights a common challenge in cybersecurity incident response. Threat intelligence firms often have a more immediate, granular view of emerging threats, while large enterprise vendors may require a higher threshold of confirmed activity before updating their public statements. Nevertheless, ServiceNow’s advisory strongly urges all customers to upgrade to patched releases as soon as possible, recognizing the potential for widespread impact.
Broader Context: ServiceNow’s Recent Security Encounters
The exploitation of CVE-2026-6875 is not an isolated incident for ServiceNow. The company has faced other security challenges recently, underscoring the persistent threats targeting enterprise software platforms. In the preceding month, ServiceNow privately disclosed a security incident where attackers had gained unauthorized access to customer data. This breach was attributed to the exploitation of an unauthenticated access flaw through a vulnerable API endpoint.

In that instance, ServiceNow’s subsequent advisory linked the incident to research efforts by security researchers or customers involved in bug bounty programs, rather than attributing it to malicious state-sponsored actors or criminal organizations. This distinction is important, as it frames the incident within the context of responsible disclosure and security testing, albeit with unintended consequences. However, the fact remains that customer data was accessed, reinforcing the need for continuous vigilance and robust security practices across the platform.
The ongoing focus on ServiceNow’s security posture, coupled with this latest exploit of CVE-2026-6875, paints a picture of a platform that, despite its sophisticated architecture and extensive security measures, remains a high-value target for threat actors. The sheer volume of sensitive data and critical business processes managed by ServiceNow instances makes them an attractive objective for a variety of malicious actors, from opportunistic cybercriminals to more sophisticated nation-state actors seeking to disrupt operations or exfiltrate intelligence.
Implications for Enterprises and the Future of AI Platform Security
The active exploitation of CVE-2026-6875 carries significant implications for businesses that rely on the ServiceNow AI Platform. The ability for unauthenticated attackers to execute code remotely within such a critical enterprise system can have cascading effects:
- Data Breach and Exfiltration: Sensitive customer data, proprietary business information, and employee records stored or processed by ServiceNow instances are at risk of being accessed and stolen.
- Service Disruption: Attackers could manipulate workflows, disable critical services, or deploy ransomware, leading to significant operational downtime and financial losses.
- Lateral Movement: A compromised ServiceNow instance can serve as a beachhead for attackers to pivot and gain access to other systems within an organization’s network, escalating the scope of the breach.
- Reputational Damage: A successful cyberattack can severely damage a company’s reputation, eroding customer trust and impacting market standing.
- Compliance Violations: Depending on the nature of the data compromised and the industry, organizations could face significant penalties for violating data protection regulations such as GDPR, CCPA, or HIPAA.
The fact that this vulnerability allows for pre-authentication exploitation is particularly concerning. It means that attackers do not need to possess valid user credentials to initiate an attack, significantly lowering the barrier to entry. This amplifies the urgency for organizations to apply the latest security patches, even if they believe their systems are not directly exposed to the internet or are otherwise secured.
The incident also highlights the evolving nature of cyber threats against AI-powered platforms. As businesses increasingly integrate AI into their core operations, the security of these platforms becomes paramount. Attackers are actively seeking to exploit vulnerabilities in AI infrastructure to compromise systems and manipulate AI-driven processes. This necessitates a proactive and multi-layered security approach that goes beyond traditional perimeter defenses.

Recommendations and Best Practices
For organizations utilizing the ServiceNow AI Platform, the following recommendations are critical:
- Immediate Patching: Prioritize the immediate application of security updates released by ServiceNow for CVE-2026-6875 across all instances, both hosted and self-hosted. This is the most crucial step in mitigating the immediate threat.
- Vulnerability Scanning and Monitoring: Conduct regular vulnerability scans and implement continuous monitoring of network traffic and system logs for any signs of suspicious activity or attempted exploitation. Pay close attention to the
/assessment_thanks.doendpoint. - Access Control Review: While this vulnerability is pre-authentication, maintaining strong access control policies for all user accounts and service accounts within ServiceNow is a fundamental security practice.
- Security Awareness Training: Ensure that IT and security teams are aware of this vulnerability and the potential implications. Educate employees about phishing attempts and social engineering tactics that could be used in conjunction with such exploits.
- Incident Response Plan: Review and update incident response plans to specifically address scenarios involving the compromise of critical enterprise platforms like ServiceNow.
- Third-Party Risk Management: For organizations that integrate third-party applications or services with ServiceNow, ensure that these integrations are also secured and regularly audited.
- Stay Informed: Keep abreast of security advisories and threat intelligence from ServiceNow and reputable cybersecurity firms like Defused and Searchlight Cyber.
The exploitation of CVE-2026-6875 serves as a stark reminder that even the most advanced enterprise platforms are not immune to sophisticated cyberattacks. The swift action by threat intelligence firms in identifying and reporting such vulnerabilities, coupled with timely patching by vendors, is essential. However, the ongoing in-the-wild exploitation underscores the need for organizations to remain vigilant, proactively manage their security posture, and be prepared to respond effectively to evolving threats in the complex cybersecurity landscape. The race to secure AI-powered enterprise infrastructure is ongoing, and the consequences of falling behind can be severe.





