news.mlab.sh
Back to the feed
vulnerability

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

High
Summary

A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow’s AI platform is being actively exploited in the wild by cybersecurity researchers, not malicious attackers. ServiceNow initially denied active exploitation but has since acknowledged the activity, urging customers to apply available patches.

A critical remote code execution vulnerability, tracked as CVE-2026-6875, exists within ServiceNow’s AI platform. This vulnerability allows an unauthenticated attacker to execute arbitrary code through a sandbox escape. Cybersecurity firm Searchlight Cyber initially disclosed technical details and a proof-of-concept for the exploit on July 14th. Threat intelligence firm Defused reported on July 18th that they were observing in-the-wild exploitation of the vulnerability, utilizing Searchlight Cyber’s provided information. ServiceNow initially stated it had no knowledge of active exploitation, and as of this writing, their advisory remains unchanged. ServiceNow has released patches to address the issue, and they are encouraging both self-hosted and ServiceNow-hosted customers to apply them. ServiceNow has clarified that the exploitation activity is being conducted by cybersecurity researchers, not malicious attackers. The vendor’s initial advisory stated it had no knowledge of active exploitation, and as of this writing, that advisory has not been updated to reflect otherwise. ServiceNow vulnerabilities are relatively uncommon in terms of exploitation by threat actors, with only two listed in CISA’s KEV catalog, both patched in 2024.

Read the full article at SecurityWeek