ServiceNow AI Platform Faces Active Exploitation of Critical Sandbox Escape Vulnerability

Attackers have commenced exploiting a critical vulnerability within the ServiceNow AI Platform, identified as CVE-2026-6875, raising significant concerns for organizations relying on the platform for their enterprise workflows and AI integration. This development comes just days after ServiceNow released security updates to address the flaw, underscoring the rapid pace at which cyber threats can evolve and be weaponized. The exploitation in the wild was first confirmed by the threat intelligence company Defused, who observed the initial attempts shortly after the patches became available.
The ServiceNow AI Platform, formerly known as the Now Platform, is a robust enterprise-grade Platform-as-a-Service (PaaS) solution. Its primary function is to empower businesses to seamlessly integrate artificial intelligence capabilities into their core operational processes. This allows for automation, enhanced decision-making, and improved efficiency across a wide range of business functions. Given its widespread adoption, particularly among large enterprises, a successful exploitation of a vulnerability within this platform can have far-reaching consequences. ServiceNow itself boasts that its AI Platform manages over 100 billion workflows annually and supports more than 100,000 enterprise AI applications, reaching an impressive 85% of all Fortune 500 companies. This broad reach amplifies the potential impact of any security compromise.
The critical vulnerability, CVE-2026-6875, was initially discovered and reported by cybersecurity firm Searchlight Cyber on April 1st. Their research detailed how the flaw allows unauthenticated threat actors to break out of the platform’s sandbox environment. This escape enables them to execute arbitrary code remotely within the ServiceNow platform, albeit in attacks characterized by high complexity. The sandbox mechanism is a crucial security feature designed to isolate processes and prevent malicious code from affecting the broader system. A successful sandbox escape therefore represents a significant breach of security, granting attackers a foothold within a highly sensitive corporate environment.

Timeline of Events and Discovery
The disclosure and subsequent exploitation of CVE-2026-6875 follow a clear, albeit concerning, chronology:
- April 1st, 2026: Cybersecurity company Searchlight Cyber publicly discloses the discovery of a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform. They detail its potential for pre-authentication remote code execution (RCE) and sandbox escape, highlighting the technical intricacies involved in such attacks.
- July 13th, 2026: ServiceNow addresses the vulnerability. For its hosted instances, the platform is patched. For self-hosted instances, security updates are released, referencing CVE-2026-6875. This release marks the official availability of protective measures against the identified flaw.
- July 14th-16th, 2026 (Over the weekend): Threat intelligence company Defused confirms that attackers have begun actively exploiting CVE-2026-6875 in real-world attacks. Their researchers observe the first attempts on Friday, indicating that exploitation began shortly after the patches were made available.
- Saturday, July 15th, 2026: Defused publicly warns about the in-the-wild exploitation via a tweet, stating, "We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875)." They note that while the initial attack vectors target the same pre-authentication sink documented by Searchlight Cyber (/assessment_thanks.do), the sandbox-escape mechanism employed by these attackers differs from the proof-of-concept (PoC) initially published. This suggests a degree of sophistication and adaptation by the threat actors.
Despite Defused’s confirmation of active exploitation, ServiceNow had not, at the time of reporting, officially flagged the security issue as actively abused. In their official advisory, the company maintained that they were "not currently aware of exploitation against ServiceNow instances." This discrepancy between threat intelligence reports and official vendor statements can create a challenging situation for security teams, who must decide whether to act on early warnings or await official confirmation.
Technical Details and Implications of the Vulnerability
CVE-2026-6875’s critical nature stems from its ability to bypass fundamental security controls. The vulnerability allows attackers to circumvent the sandbox environment, which is designed to isolate code execution. By escaping this sandbox, attackers can gain the ability to execute arbitrary code on the underlying ServiceNow platform. This opens the door to a multitude of malicious activities, including:
- Data Theft: Gaining access to sensitive customer data processed and stored within ServiceNow instances.
- System Compromise: Potentially taking control of parts of the ServiceNow environment, impacting its availability and integrity.
- Lateral Movement: Using the compromised ServiceNow instance as a pivot point to access other systems within an organization’s network.
- Disruption of Services: Interfering with the critical workflows that ServiceNow manages, leading to operational downtime and financial losses.
The fact that the vulnerability allows for pre-authentication RCE is particularly alarming. This means that an attacker does not need valid credentials to initiate the exploit, significantly lowering the barrier to entry for launching an attack. The complexity of the attacks, as noted by Searchlight Cyber, suggests that sophisticated actors or well-resourced groups might be behind these initial exploits, or that tools for exploiting this vulnerability are rapidly becoming more accessible. The observation by Defused that attackers are using a different route to achieve code execution than the published PoC indicates that threat actors are actively refining their techniques, potentially making detection more challenging for security solutions that rely on signature-based detection of the original PoC.

Broader Context: Recent Security Incidents at ServiceNow
This latest incident occurs in the shadow of another significant security event at ServiceNow. In the preceding month, the company privately disclosed a security incident where attackers successfully queried data from customer instances. This earlier breach was attributed to an unauthenticated access flaw exploited via a vulnerable API endpoint. ServiceNow later clarified that this incident was linked to security researchers or customer-led research stemming from bug bounty submissions, rather than malicious threat actors. However, the occurrence of two distinct security events involving authentication bypass and data access vulnerabilities within a relatively short period raises questions about the overall security posture and the diligence of security testing and patching processes for such a critical platform.
These past events, while perhaps not directly malicious in intent for the prior incident, highlight potential weaknesses that can be exploited. The current exploitation of CVE-2026-6875, however, is unequivocally attributed to malicious actors, making it a more immediate and direct threat. The speed at which attackers moved to exploit CVE-2026-6875 after the patches were released underscores the imperative for organizations to apply security updates promptly. The window between a patch being released and its widespread deployment is often a prime time for exploitation, as attackers race to compromise systems before defenses are fully in place.
Official Responses and Recommendations
ServiceNow has officially acknowledged the vulnerability and has urged its customers to take immediate action. The company’s advice to customers is clear: "upgrade to a patched release as soon as possible" to secure their systems against attacks. While they had not officially declared the vulnerability as actively exploited at the time of reporting, the proactive recommendation for patching implies an understanding of the potential threat.
The discrepancy between ServiceNow’s official advisory and the real-time threat intelligence from companies like Defused highlights a common challenge in cybersecurity incident response. Threat intelligence firms often operate with more immediate and granular visibility into emerging threats, while vendors may take a more measured approach to public confirmation pending thorough internal investigation. For security teams responsible for protecting enterprise systems, it is crucial to monitor advisories from both the vendor and reputable third-party threat intelligence providers.

A ServiceNow spokesperson was reportedly unavailable for immediate comment when approached by BleepingComputer to confirm Defused’s findings regarding active exploitation. This lack of immediate public comment, while understandable in a fast-moving situation, can leave customers seeking definitive confirmation.
The Importance of Proactive Security Measures
The exploitation of CVE-2026-6875 serves as a stark reminder of the critical importance of proactive security measures for all organizations, especially those relying on complex enterprise platforms like ServiceNow. The findings by Searchlight Cyber and Defused underscore the need for:
- Prompt Patch Management: Organizations must have robust patch management processes in place to ensure that security updates are applied swiftly and effectively across all relevant systems. This includes testing patches in a staging environment before full deployment to avoid introducing new issues.
- Continuous Monitoring and Threat Intelligence: Subscribing to and actively monitoring threat intelligence feeds from reputable sources is vital for staying ahead of emerging threats. Early warnings can enable organizations to implement preventative measures even before official advisories are issued.
- Security Audits and Penetration Testing: Regular security audits and penetration testing can help identify vulnerabilities before attackers do. This is particularly important for critical infrastructure and high-value targets.
- Layered Security Approach: Relying on a single security solution is rarely sufficient. A layered approach, incorporating firewalls, intrusion detection/prevention systems, endpoint detection and response (EDR), and security information and event management (SIEM) solutions, provides a more comprehensive defense.
- Incident Response Planning: Having a well-defined and practiced incident response plan is crucial for effectively managing security breaches when they occur. This plan should outline steps for containment, eradication, recovery, and post-incident analysis.
The widespread adoption of the ServiceNow AI Platform means that any successful exploitation of CVE-2026-6875 could impact a significant portion of the global business landscape. The ability for unauthenticated attackers to execute code remotely within such a critical platform represents a severe risk that demands immediate attention from IT security professionals worldwide. The ongoing situation emphasizes the constant battle between cybersecurity defenders and threat actors, where vigilance, rapid response, and a commitment to robust security practices are paramount.







