ServiceNow Sandbox Breach Escalates
Enterprise AI systems face active exploitation of a high-complexity remote code execution flaw following a recent patch release.
Enterprise environments relying on the ServiceNow AI Platform for critical business workflows are currently facing an active threat landscape. Security researchers have confirmed that malicious actors are weaponizing a critical sandbox-escape vulnerability, bypassing authentication to execute code remotely within the platform's architecture.
The Nature of the Breach
The vulnerability, tracked as CVE-2026-6875, was initially identified and reported by the team at Searchlight Cyber. As a high-complexity flaw, it allows unauthenticated attackers to escape the platform's sandbox environment. While the platform is designed to integrate AI workflows into corporate processes, this specific security gap turns that integration into a potential vector for unauthorized system control.
Timeline of Active Exploitation
ServiceNow moved to address the flaw by issuing security updates on July 13th for self-hosted instances, while simultaneously patching hosted versions of the platform. Despite these corrective measures, threat intelligence firm Defused reported on the subsequent weekend that the first in-the-wild exploitation attempts were observed on Friday. These attacks appear to be utilizing a different route to reach the code-execution primitive than the original proof-of-concept.
We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875). The payloads hit the same pre-auth sink @SLCyberSec documented (/assessment_thanks.do), but the sandbox-escape gadget reaches the same code-execution primitive by a different route than their published PoC.
— Defused, security research firm
Discrepancies in Official Stance
Despite the findings reported by external intelligence entities, the official stance from the vendor remains cautious. In its advisory, the company stated it is not currently aware of exploitation against its instances. This creates a challenging environment for IT administrators, who must weigh the company's official messaging against the confirmed activity observed by threat intelligence researchers in the field.
- 85% of all Fortune 500 companies utilize the platform.
- The platform powers more than 100 billion workflows each year.
- The system hosts over 100,000 enterprise AI applications.
Implications for Enterprise Security
This incident underscores the critical necessity for organizations to treat patch management as an urgent priority rather than a routine administrative task. The rapid transition from a vulnerability's disclosure to its active exploitation demonstrates that gaps in enterprise software are identified and weaponized within a matter of days. For companies operating at this scale, the lag between a vendor’s patch availability and the actual deployment across all instances could represent a significant exposure window. Security teams should prioritize hardening their instances against this RCE threat, as the speed of modern exploitation leaves little margin for delayed response cycles.
Sources
- BleepingComputer Original source
- CVE-2026-6875 Also reporting
- on July 13th Also reporting
Continue Reading
HAProxy Trojans Hide in South Korean Load Balancers
A Linux toolkit compiled into HAProxy binaries intercepts traffic for two South Korean firms, likely via state actors.
Chrome V8 Zero-Day Under Attack Gets Emergency Patch
Google patches a high-severity type confusion bug in V8 that has been exploited in the wild, the sixth zero-day fixed this year.
Texas, Florida Curb License Plate Surveillance
Texas and Florida are dialing back automated license plate reader use, signaling a shift in surveillance policy.