← Back to Daily Briefing

CVE-2026-6875: Pre-Authentication RCE and Sandbox Escape in ServiceNow AI Platform

Published July 20, 2026

CVE-2026-6875 is a critical pre-authentication remote code execution (RCE) vulnerability within the ServiceNow AI Platform's scripting sandbox. Unauthenticated attackers can bypass isolation boundaries to execute arbitrary code, leading to full instance compromise. The vulnerability facilitates lateral movement from cloud SaaS environments to on-premises networks via MID Server integrations and provides unauthorized access to sensitive CMDB and HR data. While patches were released for self-hosted instances on July 14, 2026, active exploitation emerged on July 17, utilizing polymorphic methodologies to circumvent initial signature-based mitigations.

  • Vulnerability Overview: Sandbox Escape

    • Identified as a critical flaw allowing unauthenticated attackers to bypass the scripting sandbox designed to isolate AI-driven code.
    • Discovered by Searchlight Cyber and reported to ServiceNow in April 2026.
    • Exploitation requires no prior authentication, significantly increasing the attack surface of the AI platform.
  • Technical Mechanics & Exploitation Trends

    • Attackers leverage a sandbox escape to move from restricted AI execution environments to the underlying system.
    • Threat intelligence from Defused indicates a shift toward polymorphic attack patterns to bypass vendor-supplied code-level mitigations.
    • Initial signature-based detection mechanisms have proven insufficient against evolving exploit payloads.
  • Systemic Impact & Blast Radius

    • Compromised AI agents grant attackers access to associated capability tokens and high-privilege service accounts.
    • Potential for "cloud-to-ground" pivoting, where attackers move from the SaaS platform into on-premises environments via MID Servers.
    • Exposure of high-value organizational data, including Human Resources records and Configuration Management Database (CMDB) assets.
  • Mitigation & Remediation Status

    • Official patches for self-hosted instances were released on July 14, 2026.
    • ServiceNow is currently investigating and implementing mitigations for hosted (SaaS) instances.
    • Security professionals are advised to prioritize MID Server hardening and token rotation for AI agents.
  • Operational Risk Analysis

    • High risk of "blind spots" during incident response if the ServiceNow ticketing system itself is the compromised vector.
    • The ability to hijack AI agent permissions expands the lateral movement potential beyond traditional user accounts.
    • Critical dependency on vendor-side updates for hosted customers, creating a window of vulnerability during the rollout.

Related posts

  1. Expert In the Cloud — Vulnerability in the ServiceNOW AI Platform
  2. helpnetsecurity.com — ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
  3. csoonline.com — ServiceNow’s sandbox escape RCE hole now exploited in the wild
  4. techjacksolutions.com — CVE-2026-6875: Active Exploitation of Critical Unauthenticated RCE in ServiceNow AI Platform Demands Immediate Patching
  5. Security Affairs — Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
  6. bleepingcomputer.com — Critical ServiceNow code execution flaw now exploited in attacks
  7. Reddit
  8. Secure
  9. Scworld
  10. Rescana
  11. Support
  12. Tenable

LINK COPIED TO CLIPBOARD