← Back to Daily Briefing

CVE-2026-6875: Pre-Authentication RCE and Sandbox Escape in ServiceNow AI Platform

Published July 21, 2026

CVE-2026-6875 is a critical pre-authentication code injection vulnerability in the ServiceNow AI Platform scripting sandbox. The flaw allows unauthenticated attackers to achieve a full sandbox escape, leading to Remote Code Execution (RCE) on the underlying host. Exploitation enables OS command execution and the creation of unauthorized administrative accounts. Furthermore, attackers can pivot from the ServiceNow cloud tenant into internal corporate networks via MID Server integrations. While patches were released on July 14, 2026, active exploitation began July 17, 2026, with threat actors utilizing adaptive payloads to bypass signature-based mitigations and the containment layer.

  • Vulnerability Mechanics: Sandbox Failure

    • Targets the containment layer of the AI Platform, allowing an attacker to break out of the isolated scripting environment.
    • Enables pre-authentication code injection, removing the need for valid credentials to initiate the attack.
    • The failure of the AI containment layer represents a fundamental security breakdown in the platform's isolation architecture.
  • Exploitation Status: Active In-the-Wild

    • Active exploitation was observed by threat intelligence firm Defused starting July 17, 2026, shortly after official patches were released.
    • Attackers are utilizing "attack method tweaks" to circumvent five specific mitigations implemented by ServiceNow.
    • Signature-based defenses are proving unreliable against the high adaptability of current Proof-of-Concept (PoC) implementations.
  • Impact and Blast Radius: Lateral Movement

    • High risk of cloud-to-on-premises lateral movement facilitated by MID Server integrations.
    • Potential exposure of critical data including HR records, CMDB asset data, and IT ticketing systems.
    • Compromise of AI agent capability tokens and delegated service account permissions, increasing the systemic blast radius.
  • Detection and Remediation: Mitigation Challenges

    • Official patches were deployed on July 14, 2026; however, they are not a total deterrent against evolving bypasses.
    • CISOs are urged to monitor MID Server logs for unusual outbound traffic or unauthorized OS-level command execution.
    • Security teams should shift toward behavioral detection rather than relying on static signatures to identify exploitation attempts.
  • Conclusion: AI-Driven Attack Surface

    • Integration of AI into privileged systems (HR, CMDB) has significantly expanded the reachable attack surface for unauthenticated actors.
    • This incident highlights the critical danger of integrating AI agents with deep system access without fail-safe, hardware-level or kernel-level isolation.

Related posts

  1. Expert In the Cloud — Vulnerability in the ServiceNOW AI Platform
  2. helpnetsecurity.com — ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
  3. csoonline.com — ServiceNow’s sandbox escape RCE hole now exploited in the wild
  4. techjacksolutions.com — CVE-2026-6875: Active Exploitation of Critical Unauthenticated RCE in ServiceNow AI Platform Demands Immediate Patching
  5. Security Affairs — Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
  6. gbhackers.com — Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
  7. falconinternet.net — CVE-2026-6875: Pre-Auth RCE in ServiceNow AI Platform Now Actively Exploited
  8. SecurityWeek — Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
  9. bleepingcomputer.com — Critical ServiceNow code execution flaw now exploited in attacks
  10. Reddit
  11. Secure
  12. Scworld
  13. Rescana
  14. Support
  15. Tenable

LINK COPIED TO CLIPBOARD