A critical remote code execution vulnerability in the ServiceNow AI platform is reportedly being exploited in the wild just days after a patch became available. The flaw, tracked as CVE-2026-6875, has been described as a sandbox escape that an unauthenticated attacker can leverage under certain conditions to execute arbitrary code.
ServiceNow announced patches on July 14, stating that hosted instances had already received the security update automatically. Self-hosted customers, however, must apply the fix themselves. On the same day, cybersecurity firm Searchlight Cyber published technical details and a proof-of-concept demonstrating how the vulnerability could be exploited.
Threat intelligence firm Defused reported on July 18 that it had observed in-the-wild exploitation of CVE-2026-6875 using information drawn from Searchlight Cyber’s disclosure. Defused initially believed the captured exploit achieved the same result as Searchlight’s proof-of-concept through a slightly different technique, but issued a correction stating that closer analysis showed the payload was in fact identical to Searchlight Cyber’s own.
ServiceNow’s original advisory stated the company had no knowledge of active exploitation, and as of this writing that advisory has not been updated. A ServiceNow spokesperson told SecurityWeek that the company is aware of the exploitation reporting but has found no evidence linking the activity to ServiceNow-hosted instances based on its investigation so far.
The company reiterated that patches are available and urged both self-hosted and hosted customers to apply them if they have not already done so, adding that it will continue working directly with customers who need assistance.
No other reports of CVE-2026-6875 exploitation have surfaced, and there is a possibility the observed activity stems from security researchers scanning for vulnerable systems rather than malicious actors. Last month, ServiceNow notified customers of a separate exploited vulnerability that was later attributed to researcher activity rather than attackers.
Limited History of Exploitation
ServiceNow vulnerabilities are not frequently weaponized by threat actors. CISA’s Known Exploited Vulnerabilities catalog currently lists only two ServiceNow flaws, both patched in 2024.
- Patch released July 14 for hosted and self-hosted instances
- Technical details and PoC published same day by Searchlight Cyber
- Exploitation reported July 18 by Defused, later confirmed to match Searchlight’s PoC
- ServiceNow says no evidence links activity to its own hosted instances
