ServiceNow sandbox escape bug now under active exploitation

Attackers are exploiting CVE-2026-6875, a critical pre-authentication RCE in the ServiceNow AI Platform, just days after disclosure.

CSBadmin
2 Min Read

A severe vulnerability in the ServiceNow AI Platform is being exploited by attackers in the wild, giving them the ability to run code remotely on self-hosted instances without any authentication, researchers from Searchlight Cyber and Defused confirmed this week.

The issue, designated CVE-2026-6875, lives in the GlideRecord query API where adding the prefix javascript: to input forces ServiceNow to interpret attacker-controlled text as executable code. The research team found a way around the platform’s sandbox through the /assessment_thanks.do endpoint, which feeds user-supplied data into a query without cleaning it first. The sandbox escape works by overwriting Object.clone with the Function constructor, tricking the sandbox into running malicious payloads outside its restricted zone.

The bug was reported to ServiceNow on April 1, 2026. Cloud-based customers got protections within 24 hours, while those running self-managed instances received patches on July 13. Defused flagged real-world exploitation starting July 17, with attackers reaching the same vulnerable endpoint through a different technique. ServiceNow’s public advisory maintains that the company is “not currently aware of exploitation” against its own cloud infrastructure.

The risk is amplified by ServiceNow’s massive footprint: the platform processes over 100 billion workflows annually and powers AI for 85 percent of Fortune 500 companies. Organizations that have not patched self-hosted deployments should treat the situation as urgent, since the gap between disclosure and live attacks closed in under three days.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.