← Back to CVE List
Vulnerability Intelligence Report
Sandbox Escape in ServiceNow AI Platform

CVE-2026-6875

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Nuclei Template
CVSS Base Score
9.5
CRITICAL
EPSS Probability:77.58%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-94 ↗CWE-94 Improper Control of Generation of Code ('Code Injection')

Affected Products & Versions

Vendor Product Affected Versions
ServiceNow ServiceNow AI Platform 0 < Australia Patch 2 (affected), 0 < Yokohama Patch 12 Hot Fix 1b (affected), 0 < Yokohama Patch 13 (affected), 0 < Zurich Patch 7b (affected), 0 < Zurich Patch 9 (affected), 0 < Brazil EA (affected), 0 < Brazil GA (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Nuclei Template
SCANNER AVAILABLE
EPSS Score
77.584%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityServiceNow · Hosted Service · USA
Reserved2026-04-22T18:21:24
Published2026-07-13T18:17:27
Last Updated2026-08-27T16:06:33

LINK COPIED TO CLIPBOARD