Threat actors are actively exploiting a critical security flaw in the ServiceNow AI Platform, identified as CVE-2026-6875, which carries a CVSS score of 9.5. This sandbox escape vulnerability allows an unauthenticated attacker to execute arbitrary code on affected instances. The exploitation was first reported by Defused Cyber, a threat intelligence firm, which observed in-the-wild attacks targeting the pre-authentication endpoint ‘/assessment_thanks.do’ via HTTP POST requests.
ServiceNow released patches throughout June 2026 for multiple versions, including Brazil EA and Brazil GA, Australia Patch 2, Zurich Patch 7b and Zurich Patch 9, and Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13. The vulnerability was disclosed by Searchlight Cyber, which reported the issue on April 1, 2026, and noted that successful exploitation could lead to complete compromise of the ServiceNow instance and all connected proxy servers.
In addition to the patch, ServiceNow is enhancing instance security by severely restricting the type of code that can run in sandbox contexts, as noted by security researcher Adam Kues. Customers using self-hosted versions are strongly advised to apply the fixes immediately to mitigate the threat.
CVEs: CVE-2026-6875
Companies: ServiceNow, Defused Cyber, Searchlight Cyber
Products: ServiceNow AI Platform
Original source: thehackernews.com