ServiceNow AI Platform CVE-2026-6875 (CVSS 9.5 Sandbox Escape) Under Active Exploitation
A ServiceNow AI Platform sandbox escape under active attack — defender teams accelerate patch verification this week.
A CVSS 9.5 sandbox escape in the ServiceNow AI Platform is reportedly being exploited days after disclosure — a verification week for defenders, not an exploitation post-mortem.
SANTA CLARA, CALIF. — A critical vulnerability in the ServiceNow AI Platform is reportedly under active exploitation, days after its disclosure and a public technical write-up. Tracked as CVE-2026-6875 and rated CVSS 9.5, the flaw is a sandbox escape that, according to the researchers who found it, can let an unauthenticated user execute arbitrary code on an affected instance. For enterprises that run ServiceNow as a platform of record, that report turns a routine patch item into an accelerated verification task.
The exploitation signal came from threat intelligence firm Defused Cyber, which said it observed in-the-wild activity against the flaw. As The Hacker News and SecurityWeek reported, the activity surfaced within days of ServiceNow shipping fixes and Searchlight Cyber publishing technical details. This is a defender-framed continuation: what was reported, what remains unconfirmed, and what customers should verify now — not a reconstruction of how the flaw is abused.
What Defused Cyber Reported
Threat intelligence firm Defused Cyber reported on July 18 that it had seen in-the-wild exploitation of CVE-2026-6875, leveraging information that Searchlight Cyber had released alongside the patch, according to SecurityWeek. The firm initially characterized the activity as reaching the same outcome as Searchlight Cyber's proof-of-concept by a slightly different method, then issued a correction stating the captured payload was in fact identical to Searchlight Cyber's own — pointing to reuse of published research rather than an independently developed capability.
ServiceNow acknowledged the reports. A spokesperson told SecurityWeek the company is aware of the publication regarding CVE-2026-6875 and that “based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts,” urging both self-hosted and ServiceNow-hosted customers to apply the relevant patches. As The Hacker News noted, ServiceNow is also restricting the type of code that can run in sandbox contexts.
Continuation Context: The Mid-July Fortinet, Ivanti, and ServiceNow Patch Cycle
CVE-2026-6875 is not a new disclosure. It was the headline item in the coordinated Fortinet, Ivanti, and ServiceNow patch cycle The CyberSignal covered earlier — a CVSS 9.5, unauthenticated remote code execution flaw in the ServiceNow AI Platform that anchored a multi-vendor release. When ServiceNow announced patches on July 14, it said a security update had been deployed to hosted instances, while self-hosted customers had to install the fixes themselves. The same day, Searchlight Cyber disclosed technical details.
ServiceNow's advisory lists fixes across multiple release trains — including its Brazil, Australia, Zurich, and Yokohama families. What has changed since that cycle is not the fix but the threat context: a critical, unauthenticated flaw with a public technical write-up has now drawn reported exploitation attempts within days. That compression between disclosure and exploitation is why anyone who deferred the ServiceNow item should revisit it now.
Defender Posture for ServiceNow AI Platform Customers
The first task is inventory and confirmation. ServiceNow says it deployed the fix to hosted instances, so for those customers the defender action is verification that the update landed rather than manual patching. Self-hosted and partner deployments are the exposure that matters most: they require applying the vendor-provided update and confirming it. That is the same discipline behind patch management generally: in complex estates the gap between “patch issued” and “patch confirmed” is where risk persists.
The second task is prioritization by severity and exposure. A CVSS 9.5 that an unauthenticated actor can reach belongs at the top of the queue regardless of exploitation status, because the score already encodes high impact and the access barrier is effectively zero. The ServiceNow AI Platform's role sharpens the stakes: it layers AI-assisted workflows on a system many enterprises use for IT service management, HR, and security operations, so a flaw there sits close to a platform of record. It fits a pattern The CyberSignal has tracked as vulnerability exploitation overtook credential theft as the leading initial-access vector, echoing recent cases such as Palo Alto GlobalProtect, where exploitation followed disclosure closely. Structured vulnerability management is what converts a severity score into an executed fix.
What a CISA KEV Addition Should Signal
As of this writing, CVE-2026-6875 is not listed in CISA's Known Exploited Vulnerabilities catalog. SecurityWeek notes that ServiceNow vulnerabilities are rarely exploited by threat actors — the KEV catalog currently includes only two ServiceNow flaws, both patched in 2024 — and raises the possibility that some observed activity may be security-industry researchers scanning for vulnerable systems rather than adversaries. That uncertainty is worth holding onto, but it is not a reason to defer a 9.5-rated, unauthenticated patch.
A KEV listing, if it comes, would be the strongest independent confirmation that the exploitation is adversarial and worth treating as an active-incident driver. For federal agencies it would also start a remediation clock under CISA's risk-based directive, BOD 26-04. Private-sector defenders should watch the catalog as a signal rather than a starting gun: the reported exploitation and the CVSS 9.5 rating already justify moving now, and a KEV entry would only harden the case — a pattern seen when the Ivanti Sentry flaws were exploited and added to KEV within a day.
Open Questions
Several specifics remain unconfirmed. No threat actor has been named, and there is no confirmed figure for how many ServiceNow AI Platform instances are exposed or affected. It is not yet established whether the observed activity is adversarial or security-industry researchers probing for vulnerable systems — SecurityWeek explicitly flags that ambiguity, and Defused Cyber's own correction narrowed the picture. CVE-2026-6875 is not in CISA's KEV catalog at the time of writing.
The precise affected and patched build levels are best read from ServiceNow's own advisory, which customers should treat as authoritative for scope, versions, and remediation. The core facts — a CVSS 9.5, unauthenticated sandbox-escape flaw in the ServiceNow AI Platform, reportedly exploited days after disclosure and already patched in the mid-July cycle — are well supported by ServiceNow's statements and independent coverage; the operational details should be verified against the vendor advisory before action.
The CyberSignal Analysis
The reported facts above are Defused Cyber's, ServiceNow's, and the cited outlets'; what follows is The CyberSignal's editorial reading of what defenders should take from them. None of the judgments below are new reported facts.
Signal 01 — Public PoC Plus Unauthenticated Critical Compresses the Timeline
The most useful way to read CVE-2026-6875 is as a scheduling instruction, not a branding story. Our assessment is that the urgency comes from the pairing of critical severity, no authentication requirement, and a published technical write-up: once a working method is public, the distance between disclosure and opportunistic exploitation collapses to days, as it did here. Defenders who treat “CVSS 9.5, unauthenticated, PoC available” as an automatic top-of-queue trigger — independent of confirmed adversary activity — close the window before it is tested.
Signal 02 — The Delivery Model Decides Where the Real Risk Sits
ServiceNow's split rollout — automatic for hosted instances, manual for self-hosted customers and partners — means the same CVE implies very different work depending on how the platform is consumed. Our reading is that residual risk concentrates in self-hosted and partner deployments, where the fix does not arrive on its own and confirmation is the customer's job. The forward-looking implication is to pre-classify the ServiceNow estate by hosting model now, so the next critical advisory converts immediately into the right action.
Signal 03 — Watch KEV as Confirmation, Not as the Trigger
The open question of whether this activity is adversarial or researcher-driven is real, and a CISA KEV listing would resolve much of it. Our assessment is that defenders should watch the catalog as a confirmation signal while acting ahead of it: the reported exploitation, the public PoC, and the 9.5 rating already meet the bar for prioritized remediation. Waiting for a KEV entry to begin work inverts the risk calculus: by the time a flaw is cataloged as exploited, the window has usually been open for days.