ServiceNow disclosed and remediated CVE-2026-6875, a critical sandbox escape in its AI Platform that can allow unauthenticated remote code execution in certain circumstances. The vulnerability affects both hosted and self-hosted ServiceNow environments, carries a CVSS 4.0 score of 9.5, and was published in advisory KB3137947. ServiceNow said it has already deployed security updates to hosted instances and issued patched family releases and updates for self-hosted customers and partners.
The company said it is not currently aware of active exploitation, but warned that successful compromise could let attackers execute code within the ServiceNow platform, disrupt workflows, access sensitive data, modify records, and enable follow-on malicious activity. To reduce near-term exploit risk, ServiceNow limited public technical details while directing customers to promptly apply the relevant updates or upgrade to patched releases, including fixes for the Brazil, Australia, Zurich, and Yokohama release families.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
A new report says technical details and proof-of-concept exploit code for CVE-2026-6875 were publicly disclosed, increasing the risk of broader exploitation of the ServiceNow AI Platform flaw. The report describes attacks against the pre-authentication /assessment_thanks.do endpoint using crafted payloads to achieve sandbox escape and remote code execution.
After initially reporting that in-the-wild exploitation used a different sandbox-escape path, Defused later corrected its assessment and said the captured payload was identical to Searchlight Cyber’s published proof-of-concept. The update suggested some observed activity may have come from researchers rather than threat actors.
Defused reported that attackers began exploiting CVE-2026-6875 in the wild only days after ServiceNow released patches. The attacks targeted the /assessment_thanks.do pre-authentication sink and used a different sandbox-escape path than the previously published proof of concept.
Following CVE-2026-6875, ServiceNow introduced stricter sandbox protections called Guarded Script to reduce the likelihood of future sandbox escapes. The change is described as an additional hardening measure beyond the immediate mitigation and released patches.
ServiceNow said it addressed CVE-2026-6875 by deploying security updates to hosted instances and releasing patched family versions and updates for self-hosted customers and partners. The remediation covered affected releases including Brazil, Australia, Zurich, and Yokohama.
On 2026-07-13, ServiceNow published advisory KB3137947 disclosing CVE-2026-6875, a critical sandbox escape in its AI Platform that could enable unauthenticated remote code execution. The company said it was not aware of active exploitation at the time.
According to the new reference, researchers reported CVE-2026-6875 to ServiceNow on 2026-04-01. The vendor reportedly deployed an immediate mitigation for cloud instances within 24 hours, ahead of the broader July advisory and fixes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
22 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcethreataft.com
Open sourcereddit.com
Open sourcecvefeed.io
Open sourceassetnote.io
Open sourcefortiguard.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.