NowBen Cert eBook – Billboard – 0726
News

Hackers Exploit ServiceNow AI Platform Vulnerability: What You Need to Do Now

By Sasha Semjonova

ServiceNow’s AI platform is allegedly being targeted by attackers exploiting a critical vulnerability known as CVE-2026-6875. 

This vulnerability is the same one discovered by cybersecurity company Searchlight Cyber, which reported on it on April 1, 2026. It allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform. 

Active Attacks

According to threat intelligence company Defused, it is currently observing an “in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875).” It allows a complete compromise of the ServiceNow instance as well as all connected proxy servers. 

This particular vulnerability was first discovered by Searchlight Cyber two months prior, which ServiceNow responded to by releasing an update that resolved the issue. At the time, it was unclear whether or not the vulnerability had been exploited, with the ITSM leader simply reporting that it had been detecting some “anomalous activity” related to the breach. 

READ MORE: Customer Data Exposed to Hacking Risk in New ServiceNow Vulnerability

Initially, Defused thought that the payloads hit the same pre-auth sink Searchlight Cyber had previously documented (assessment_thanks.do), but the sandbox-escape gadget reaches the same code-execution primitive by a different route than their published PoC.

Shortly after, it corrected its statement, explaining that the captured payload matches Searchlight Cyber’s final validation payload verbatim, with only the canary being different. 

What Happens Now?

ServiceNow addressed the vulnerability across hosted instances starting in April. It then released CVE-2026-6875 security updates for self-hosted instances one week ago, on July 13. The subsequent attacks began over the weekend. 

However, ServiceNow has yet to flag this exploitation, stating in its official advisory that it was “not currently aware of exploitation against ServiceNow instances.”

A ServiceNow spokesperson told NowBen that the company “has not observed evidence that this [exploitation] activity is related to instances that ServiceNow hosts.”

“We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so,” they said. “In addition, we will continue to work directly with customers who need assistance in applying the patches.

What Do I Need to Do?

The official guidance from ServiceNow is to promptly apply appropriate updates or upgrade to a patched release if they have not already done so. A security update addressing the vulnerability had been deployed to hosted instances. Self-hosted customers will need to install the necessary patches themselves. 

The updates and patches include:

  • Brazil: Brazil Early Access & Brazil General Availability
  • Australia: Australia Patch 2
  • Zurich: Zurich Patch 7b & Zurich Patch 9
  • Yokohama: Yokohama Patch 12 Hot Fix 1b & Yokohama Patch 13

More information can be found on this support page

READ MORE: Agentic AI Security in ServiceNow: Experts Explain Key Concepts You Need to Know

Final Thoughts

Whether or not this particular vulnerability is directly related to live ServiceNow instances, the advice remains the same. Install updates and patches as required to avoid putting your business and instance at risk. 

ServiceNow has also encouraged customers to contact the ServiceNow Technical Support team for further assistance if necessary. 

The Author

Sasha Semjonova

Sasha is a Reporter at NowBen.

Leave a Reply