- Threat actors are actively exploiting CVE-2026-6875, a critical sandbox escape vulnerability in the ServiceNow AI Platform.
- The flaw, rated 9.5 on the CVSS scale, allows unauthenticated remote code execution and complete compromise of a ServiceNow instance.
- ServiceNow released patches throughout June, and self-hosted customers are urged to apply fixes immediately.
Threat intelligence firm Defused Cyber is now observing in-the-wild exploitation of a recently disclosed critical security flaw impacting the ServiceNow AI Platform, according to a post shared on X. The vulnerability, tracked as CVE-2026-6875 with a CVSS score of 9.5, is a sandbox escape flaw that could allow an unauthenticated user to run arbitrary code.
ServiceNow released patches for the bug throughout June across several versions, including Brazil, Australia Patch 2, and multiple Zurich and Yokohama updates. Searchlight Cyber, which disclosed additional technical specifics, said it reported the issue on April 1, 2026, adding it allows a complete compromise of the ServiceNow instance as well as all connected proxy servers.
ServiceNow is enhancing instance security by severely restricting the type of code that can run in sandbox contexts, according to security researcher Adam Kues. According to Defused, the exploitation efforts target the same pre-authentication endpoint (“/assessment_thanks.do”) using HTTP POST requests, although the sandbox-escape gadget leads to the same code execution primitive by a different route documented in the proof-of-concept exploit. Customers of self-hosted versions are advised to apply the fixes, if not already, to counter the threat.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
