A critical ServiceNow RCE vulnerability is now reportedly being exploited in attacks, days after security updates became available for self-hosted instances.
The flaw, tracked as CVE-2026-6875, affects the ServiceNow AI Platform. Security researchers warn that an unauthenticated attacker could escape the platform’s sandbox and execute code remotely in complex attack scenarios.
ServiceNow has already applied a fix to its hosted instances. However, organisations running self-hosted deployments should install the available security updates as soon as possible.
Researchers Report Active Exploitation
Threat-intelligence company Defused said it observed attempts to exploit CVE-2026-6875 on July 17.
The reports emerged shortly after ServiceNow released patches for self-hosted customers on July 13. According to Defused, attackers are using a different route to reach the same remote-code-execution outcome described in the original research.
At the time of reporting, ServiceNow had not confirmed active exploitation in its official advisory. The company continued to state that it was not aware of attacks targeting customer instances.
Nevertheless, reports from independent researchers suggest that organisations should treat the ServiceNow RCE vulnerability as an urgent patching priority.
What Is CVE-2026-6875?
CVE-2026-6875 is a pre-authentication sandbox-escape vulnerability. In other words, an attacker may not need valid login credentials before attempting to exploit the issue.
The vulnerability was discovered by Searchlight Cyber and privately reported to ServiceNow on April 1.
Researchers said a successful attack could allow a threat actor to escape restrictions designed to isolate code within the ServiceNow environment. From there, the attacker could potentially run code remotely on the affected platform.
Remote code execution vulnerabilities are particularly serious because they can give attackers a path to steal data, deploy malware, create persistence, or move further into connected enterprise systems.
Hosted Customers Have Been Patched
ServiceNow addressed the ServiceNow RCE vulnerability across its hosted environments. Therefore, customers using the company-managed platform should already be protected by the vendor’s remediation work.
However, self-hosted customers remain responsible for applying the relevant updates.
Organisations should first identify all ServiceNow instances in their environment. They should then confirm the version currently in use and upgrade any affected self-hosted deployment to a patched release.
Security teams should also check whether patching has completed successfully across development, test, disaster-recovery, and production environments.
Why the Risk Matters for Businesses
The ServiceNow AI Platform supports key enterprise workflows, including IT service management, security operations, customer support, and automated business processes.
ServiceNow says its platform powers more than 100 billion workflows each year and supports over 100,000 enterprise AI applications. It is also used by a large share of Fortune 500 companies.
As a result, a successful compromise could affect systems that manage sensitive business data and core operational services.
The company also disclosed a separate security incident last month involving unauthenticated access to customer-instance data through a vulnerable API endpoint. ServiceNow later attributed that activity to security research and bug-bounty-related testing rather than malicious attackers.
What Organisations Should Do Next
Organisations using self-hosted ServiceNow should apply the CVE-2026-6875 fixes immediately.
In addition, security teams should review logs for unusual activity, unexpected requests, unfamiliar administrator actions, and suspicious outbound network connections. They should also verify that access controls and monitoring systems are working as intended.
Finally, businesses should ensure that their incident-response plans cover critical third-party platforms. The reported exploitation of this ServiceNow RCE vulnerability shows how quickly attackers can begin targeting high-severity flaws after patches become public.


0 responses to “ServiceNow RCE Vulnerability Now Exploited in Attacks”