ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

criticalExploit / PoC exploited in the wildimportance 60CVE-2026-6875

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-6875
Unauthenticated Remote Code Execution in ServiceNow AI Platform

ServiceNow has patched a critical, unauthenticated remote code execution vulnerability (CWE-94, code injection) in the ServiceNow AI platform that is reachable over the network without credentials or user interaction, though exploitation requires certain circumstances to be met (CVSS 4.0 attack complexity is high). A remote attacker who successfully triggers the flaw can execute code within the ServiceNow platform, with potentially high impact on the confidentiality, integrity, and availability of the instance and its data. Both ServiceNow-hosted (SaaS) instances and self-hosted customer and partner deployments are affected; hosted instances were fixed via a centrally deployed security update, while self-hosted customers and partners must apply the provided security updates or patched family releases themselves. ServiceNow's advisory states it was not initially aware of exploitation, but subsequent security reporting indicates this pre-auth RCE has been exploited in the wild. There is no known public proof-of-concept and the flaw is not yet in CISA's KEV catalog, but EPSS assigns a 77.6% probability of exploitation within 30 days.

Do: Self-hosted customers and partners should immediately apply the released security updates or upgrade to the patched family releases, as specific affected version numbers were not disclosed. Hosted customers should verify with ServiceNow that their instance received the centrally deployed update and confirm their current patch level. Given reports of in-the-wild exploitation, review instance logs for signs of unauthenticated code execution and restrict external access to instances where feasible.

9.578%
  • ServiceNow AI Platform (hosted/SaaS instances)
  • ServiceNow AI Platform (self-hosted customer and partner deployments)
massmillions of end users across tens of thousands of hosted and self-hosted ServiceNow instances (no public count of AI-platform-enabled instances)
Full article423 words · extracted from helpnetsecurity.com · click to collapse

Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused.

About the vulnerability

ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows.

CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance.

The vulnerability was unearthed by Searchlight Cyber researchers and reported to ServiceNow in early April 2026.

The latter company pushed out a security update to hosted instances the very next day, and made patches and security updates available to self-hosted customers and partners throughout June.

The existence of CVE-2026-6875 was publicly revealed on July 13. The security advisory and warning were followed by Searchlight Cyber’s very technical post detailing the flaw.

Researcher Adam Kues describes it as exploitable in high-complexity attacks, but allowing unauthenticated code execution and full compromise of the ServiceNow instance and any connected proxy servers.

Exploitation in the wild

Defused researchers say the first exploitation attempts appeared on Friday and confirmed active in-the-wild abuse over the weekend.

They said that the observed payloads hit the same pre-authentication endpoint (/assessment_thanks.do) that Searchlight Cyber documented in its public research, but the attackers’ sandbox-escape gadget reaches the same code-execution primitive by a different route than the one in the published proof-of-concept.

With this in mind, administrators of self-hosted instances who have not yet applied the July 13th update should do so now.

The security updates also carry Guarded Script, a new feature that restricts the type of code that can run in sandbox contexts, thus making future sandbox escapes less likely.

UPDATE (July 20, 2026, 04:30 p.m. ET):

“ServiceNow is aware of a cybersecurity company’s recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as CVE-2026-6875. Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts,” a ServiceNow spokesperson told Help Net Security.

“We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so. In addition, we will continue to work directly with customers who need assistance in applying the patches.”

This article has also been amended to reflect the fact that ServiceNow pushed patches to customers throughout June (and not in last week, as previously stated).

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/