Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
A critical security flaw (CVE-2026-6875) in the ServiceNow AI Platform is being actively exploited in the wild, allowing unauthenticated users to execute arbitrary code.
Intelligence analysis by Gemini 2.5 Flash

Threat actors are leveraging a sandbox escape vulnerability in ServiceNow's AI Platform to gain unauthorized access and run malicious code. This flaw, which carries a CVSS score of 9.5, enables a complete compromise of affected ServiceNow instances and connected proxy servers, prompting urgent patching recommendations.
Imagine a big computer system that helps a company run smoothly, like a super-smart assistant. This assistant has a special 'brain' that uses AI. Someone found a secret trick, like a hidden back door, to sneak into this assistant's brain without needing a password. Once inside, they can tell the assistant to do anything they want, which is a big problem because they could mess things up or steal secrets. The company has now given everyone a special 'fix' to close that back door, so it's super important for companies to use it right away.
Analysis
Unauthenticated Code Execution on ServiceNow
ServiceNow, a prominent provider of digital workflow solutions, is grappling with a critical security vulnerability, CVE-2026-6875, affecting its AI Platform. This flaw, rated with a severe CVSS score of 9.5, is categorized as a sandbox escape vulnerability. Its severity stems from the fact that it allows an unauthenticated user to execute arbitrary code on affected instances. This means an attacker doesn't need legitimate credentials to gain control, significantly lowering the bar for exploitation and increasing the potential impact on organizations relying on ServiceNow for their operations.
The vulnerability was initially reported by Searchlight Cyber on April 1, 2026, highlighting its potential for a complete compromise of the ServiceNow instance, extending even to connected proxy servers. Such a broad impact underscores the architectural significance of the flaw, suggesting it could bypass multiple layers of security designed to isolate and protect core systems. The disclosure of technical specifics by Searchlight Cyber likely provided threat actors with the necessary information to develop and deploy exploits, accelerating the timeline from disclosure to active exploitation.
The Active Exploitation Campaign
Threat intelligence firm Defused Cyber has confirmed active exploitation of CVE-2026-6875 in the wild. Attackers are targeting a specific pre-authentication endpoint, "/assessment_thanks.do," using HTTP POST requests. While the exact sandbox-escape gadget used in these attacks may differ from publicly documented proof-of-concept (PoC) exploits, the ultimate outcome remains the same: arbitrary code execution. This indicates that threat actors are adapting their methods or discovering alternative routes to achieve the same critical primitive, demonstrating a sophisticated understanding of the vulnerability and the underlying platform.
The observed exploitation efforts underscore the urgency for organizations to apply patches. The fact that attackers are actively leveraging this flaw means that any unpatched ServiceNow instance is a direct target, facing imminent risk of compromise. The use of a pre-authentication endpoint is particularly concerning, as it allows attackers to initiate their malicious activities without needing to bypass any initial authentication mechanisms, making the attack surface much larger and easier to target.
Mitigating the Critical Threat
ServiceNow has responded to the vulnerability by releasing patches throughout June 2026 across various versions, including Brazil EA and GA, Australia Patch 2, Zurich Patch 7b and 9, and Yokohama Patch 12 Hot Fix 1b and Patch 13. These updates are crucial for mitigating the risk posed by CVE-2026-6875. Beyond just patching, ServiceNow is also enhancing instance security by severely restricting the type of code that can run in sandbox contexts, a proactive measure aimed at preventing similar sandbox escape vulnerabilities in the future.
For customers running self-hosted versions of ServiceNow, the immediate application of these fixes is paramount. Organizations must prioritize patching efforts to protect their instances from ongoing exploitation. Failure to do so could lead to unauthorized access, data exfiltration, system disruption, and significant reputational damage. The combination of active exploitation and the critical nature of the flaw makes this a top-tier security concern requiring swift and decisive action from all affected ServiceNow users.
Key points
- A critical security flaw (CVE-2026-6875) in the ServiceNow AI Platform allows unauthenticated code execution.
- The vulnerability, a sandbox escape, has a CVSS score of 9.5 and can lead to a complete compromise of ServiceNow instances and connected proxy servers.
- Threat intelligence firm Defused Cyber has confirmed active exploitation of the flaw in the wild, targeting a pre-authentication endpoint.
- ServiceNow released patches throughout June 2026 for various versions and is enhancing security by restricting code in sandbox contexts.
- Customers with self-hosted ServiceNow instances are strongly advised to apply the fixes immediately to mitigate the threat.
ServiceNow has promptly released patches for the critical flaw across multiple versions, providing a clear path for customers to secure their systems. Additionally, the company is enhancing overall instance security by restricting code execution in sandbox contexts, which could prevent similar vulnerabilities from emerging in the future.
Given the active exploitation of this critical vulnerability, organizations that fail to apply the necessary patches immediately face a high risk of unauthenticated code execution, leading to complete system compromise, data breaches, and significant operational disruption.


