
CVE-2026-6875: ServiceNow AI Platform — Pre-auth RCE Threat Escalates (July 2026)
CVE-2026-6875 — ServiceNow AI Platform
CVE-2026-6875 is a critical vulnerability (severity: critical) in the ServiceNow AI Platform, enabling unauthenticated remote code execution and sandbox escape on self-hosted instances. Active exploitation in the wild began prior to July 20, 2026, with attackers targeting unpatched environments. No confirmed breaches have occurred on ServiceNow-hosted instances, but self-hosted deployments are at immediate risk.
Attack Vector
Attackers exploit CVE-2026-6875 by sending crafted requests to exposed ServiceNow AI Platform endpoints, requiring no authentication. Successful exploitation grants full code execution privileges on the target instance and can lead to sandbox escape, allowing lateral movement to connected proxy servers or internal assets. The attack is pre-auth and does not require user interaction, making it highly attractive for automated exploitation campaigns. Indicators of compromise (IOCs) are not specified, but anomalous requests to AI Platform endpoints should be scrutinized.
Who Is at Risk
All organizations running self-hosted ServiceNow AI Platform instances are vulnerable. ServiceNow-hosted (SaaS) environments have not shown evidence of compromise, but patching is recommended for all deployment types. Organizations with exposed AI Platform endpoints or proxy integrations are especially at risk of full environment compromise.
Patch & Mitigate
- Patch: Apply the official ServiceNow security update for CVE-2026-6875 to all self-hosted AI Platform instances immediately. ServiceNow has released patches for both self-hosted and hosted environments as of July 20, 2026.
- Workaround: If patching is delayed, restrict network access to AI Platform endpoints and disable unnecessary integrations until remediation is complete.
- Detect: Monitor logs for unauthenticated or anomalous requests to AI Platform endpoints, especially those originating from unfamiliar IP addresses or outside normal business hours. Review proxy server logs for unexpected lateral movement.
MITRE ATT&CK
- TA0001 — Initial Access: Attackers leverage unauthenticated access to gain a foothold via exposed endpoints.
- TA0007 — Discovery: Post-exploitation, adversaries may enumerate connected proxy servers and internal assets for lateral movement.
Source: https://www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

