ServiceNow Sandbox Breach Escalates
Enterprise AI systems face active exploitation of a high-complexity remote code execution flaw following a recent patch release.
Enterprise environments relying on the ServiceNow AI Platform for critical business workflows are currently facing an active threat landscape. Security researchers have confirmed that malicious actors are weaponizing a critical sandbox-escape vulnerability, bypassing authentication to execute code remotely within the platform's architecture.
The Nature of the Breach
The vulnerability, tracked as CVE-2026-6875, was initially identified and reported by the team at Searchlight Cyber. As a high-complexity flaw, it allows unauthenticated attackers to escape the platform's sandbox environment. While the platform is designed to integrate AI workflows into corporate processes, this specific security gap turns that integration into a potential vector for unauthorized system control.
Timeline of Active Exploitation
ServiceNow moved to address the flaw by issuing security updates on July 13th for self-hosted instances, while simultaneously patching hosted versions of the platform. Despite these corrective measures, threat intelligence firm Defused reported on the subsequent weekend that the first in-the-wild exploitation attempts were observed on Friday. These attacks appear to be utilizing a different route to reach the code-execution primitive than the original proof-of-concept.
We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875). The payloads hit the same pre-auth sink @SLCyberSec documented (/assessment_thanks.do), but the sandbox-escape gadget reaches the same code-execution primitive by a different route than their published PoC.
— Defused, security research firm
Discrepancies in Official Stance
Despite the findings reported by external intelligence entities, the official stance from the vendor remains cautious. In its advisory, the company stated it is not currently aware of exploitation against its instances. This creates a challenging environment for IT administrators, who must weigh the company's official messaging against the confirmed activity observed by threat intelligence researchers in the field.
- 85% of all Fortune 500 companies utilize the platform.
- The platform powers more than 100 billion workflows each year.
- The system hosts over 100,000 enterprise AI applications.
Implications for Enterprise Security
This incident underscores the critical necessity for organizations to treat patch management as an urgent priority rather than a routine administrative task. The rapid transition from a vulnerability's disclosure to its active exploitation demonstrates that gaps in enterprise software are identified and weaponized within a matter of days. For companies operating at this scale, the lag between a vendor’s patch availability and the actual deployment across all instances could represent a significant exposure window. Security teams should prioritize hardening their instances against this RCE threat, as the speed of modern exploitation leaves little margin for delayed response cycles.
Continue Reading
Critical Command Injection Flaw in AVideo
An incomplete patch in AVideo versions before 29.0 allows unauthenticated attackers to execute arbitrary OS commands via the Live plugin.
LightRAG Critical CORS Flaw Enables Data Theft
A critical vulnerability in LightRAG allows unauthorized cross-origin requests, potentially exposing sensitive documents and knowledge graph data.
LightRAG Critical Auth Bypass Vulnerability
A hardcoded secret in LightRAG allows unauthenticated attackers to bypass API key protections and gain full control over document operations.
Sources
- CVE-2026-6875
- found this critical vulnerability
- on July 13th
- privately disclosed a security incident
- Test every layer before attackers do
- Critical Langflow RCE flaw exploited to hack AI app servers
- CISA: Microsoft SharePoint RCE flaw now actively exploited
- CISA sets urgent deadline to fix Cisco flaw exploited in attacks
- Critical Windows Netlogon RCE flaw now exploited in attacks
- Critical Fortinet FortiSandbox flaws now exploited in attacks