← Back to Daily Briefing

CVE-2026-6875: Critical Pre-Authentication RCE in ServiceNow AI Platform

Published July 21, 2026

CVE-2026-6875 is a critical pre-authentication vulnerability in the ServiceNow AI Platform that allows unauthenticated attackers to execute arbitrary code via a scripting sandbox escape. By leveraging code injection to bypass containment layers, attackers achieve Remote Code Execution (RCE) within the platform. The vulnerability is actively exploited in the wild, with threat actors utilizing polymorphic payloads to evade multiple vendor-issued mitigations. The primary risk involves the compromise of privileged AI agent capability tokens and the potential for lateral movement from cloud-hosted SaaS environments to on-premises corporate networks through MID Server integrations, threatening sensitive HR, CMDB, and ticketing data.

  • Vulnerability Mechanics: Sandbox Escape

    • Attackers utilize pre-authentication code injection to penetrate the AI Platform's scripting sandbox.
    • The flaw represents a fundamental failure in the "containment" model used to isolate AI-driven scripts.
    • Exploitation involves bypassing five distinct ServiceNow mitigations using evolving, polymorphic payloads.
  • Exploitation Status and Evasion

    • Searchlight Cyber discovered and reported the vulnerability in April 2026.
    • Threat intelligence from Defused confirms that active exploitation has evolved beyond initial proof-of-concept (PoC) methodologies.
    • Traditional signature-based defenses are currently insufficient against the polymorphic nature of the observed attacks.
  • Systemic Impact and Blast Radius

    • Compromised environments risk exposure of HR records, CMDB asset data, and IT ticketing system contents.
    • Attackers specifically target AI Agent capability tokens and delegated service accounts to achieve privilege escalation.
    • The blast radius is significantly expanded by the intrinsic high-level permissions granted to AI agents for enterprise automation.
  • Infrastructure Risk: SaaS-to-On-Premises Lateral Movement

    • The vulnerability creates a high-risk bridge between cloud-hosted SaaS tenants and internal corporate networks.
    • MID Server integrations serve as the primary vector for lateral movement into on-premises environments.
    • Strategic analysis by IDC highlights this as a critical failure of modern SaaS architecture boundaries.
  • Defensive Recommendations and Conclusion

    • Immediate deployment of all vendor patches is mandatory, though not a guarantee against polymorphic variants.
    • Security teams must implement rigorous monitoring of MID Server logs for anomalous outbound connections.
    • Organizations should audit and restrict permissions assigned to AI Agent capability tokens and associated service accounts.

Related posts

  1. Expert In the Cloud — Vulnerability in the ServiceNOW AI Platform
  2. helpnetsecurity.com — ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
  3. csoonline.com — ServiceNow’s sandbox escape RCE hole now exploited in the wild
  4. techjacksolutions.com — CVE-2026-6875: Active Exploitation of Critical Unauthenticated RCE in ServiceNow AI Platform Demands Immediate Patching
  5. bleepingcomputer.com — Critical ServiceNow code execution flaw now exploited in attacks
  6. feeds.feedburner.com — ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
  7. Reddit
  8. Secure
  9. Scworld
  10. Rescana
  11. Support
  12. Tenable
  13. SecurityWeek — Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow

LINK COPIED TO CLIPBOARD