ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused.
About the vulnerability
ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows.
CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance.
The vulnerability was unearthed by Searchlight Cyber researchers and reported to ServiceNow in early April 2026.
The latter company pushed out a security update to hosted instances the very next day, and made patches and security updates available to self-hosted customers and partners throughout June.
The existence of CVE-2026-6875 was publicly revealed on July 13. The security advisory and warning were followed by Searchlight Cyber’s very technical post detailing the flaw.
Researcher Adam Kues describes it as exploitable in high-complexity attacks, but allowing unauthenticated code execution and full compromise of the ServiceNow instance and any connected proxy servers.
Exploitation in the wild
Defused researchers say the first exploitation attempts appeared on Friday and confirmed active in-the-wild abuse over the weekend.
They said that the observed payloads hit the same pre-authentication endpoint (/assessment_thanks.do) that Searchlight Cyber documented in its public research, but the attackers’ sandbox-escape gadget reaches the same code-execution primitive by a different route than the one in the published proof-of-concept.
With this in mind, administrators of self-hosted instances who have not yet applied the July 13th update should do so now.
The security updates also carry Guarded Script, a new feature that restricts the type of code that can run in sandbox contexts, thus making future sandbox escapes less likely.
UPDATE (July 20, 2026, 04:30 p.m. ET):
“ServiceNow is aware of a cybersecurity company’s recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as CVE-2026-6875. Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts,” a ServiceNow spokesperson told Help Net Security.
“We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so. In addition, we will continue to work directly with customers who need assistance in applying the patches.”
This article has also been amended to reflect the fact that ServiceNow pushed patches to customers throughout June (and not in last week, as previously stated).

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
