Attackers are actively exploiting CVE-2026-6875, a critical pre-auth sandbox-escape RCE in the ServiceNow AI Platform, using a different route than the published proof of concept. ServiceNow has patched hosted instances and released updates for self-hosted deployments, but Defused says exploitation began in the wild soon after the fix was issued. #ServiceNow #CVE-2026-6875 #Defused #SearchlightCyber
Keypoints
- CVE-2026-6875 affects the ServiceNow AI Platform, formerly known as the Now Platform.
- The flaw enables unauthenticated attackers to escape the sandbox and execute remote code.
- Searchlight Cyber discovered and reported the vulnerability on April 1.
- Defused confirmed in-the-wild exploitation beginning on Friday after ServiceNowβs July 13 patch release.
- ServiceNow says it is not currently aware of exploitation, but urges customers to upgrade immediately.