CVE-2026-6875 is a critical sandbox escape vulnerability in the ServiceNow AI Platform that could enable unauthenticated remote code execution under certain circumstances.
ServiceNow deployed security updates to hosted instances on July 14, while self-hosted ServiceNow customers must apply the provided patches.
Defused reported observing exploitation activity only days after technical details became public.
Organizations should verify patch status, review logs, and monitor administrative activity associated with ServiceNow environments.
CVE-2026-6875 quickly progressed from public disclosure to reported exploitation, reducing the response window for affected ServiceNow AI Platform deployments. The sandbox escape vulnerability could enable unauthenticated remote code execution (RCE) under certain circumstances.
ServiceNow announced security updates on July 14, 2026, deploying them to hosted instances while requiring self-hosted ServiceNow customers to apply the patches. Searchlight Cyber published technical details the same day, and Defused reported in-the-wild exploitation on July 18. ServiceNow said it found no evidence linking the reported activity to its hosted instances.
The incident highlights the need to treat AI platform components as part of the enterprise attack surface, especially when they support IT service management, automation, privileged operations, and enterprise integrations.
ServiceNow CVE-2026-6875 was reportedly exploited within days of public disclosure, leaving organizations less time to validate exposure and apply patches.
According to ServiceNow and the National Vulnerability Database, the flaw is a sandbox escape in the ServiceNow AI Platform that could allow unauthenticated remote code execution under certain circumstances. It has a CVSS score of 9.5 (Critical).
Following ServiceNow’s patch release, Searchlight Cyber published technical details, and Defused reported observing exploitation days later using information released by Searchlight Cyber. The sequence shows how quickly organizations may need to respond once exploit details become public.
Top 10 Cybersecurity Challenges for Enterprises
Explore the top enterprise cybersecurity challenges and practical strategies to reduce risk.
Patch Status Matters More Than Disclosure Timing
One of the most important operational details in this incident is the difference between hosted and self-hosted deployments.
ServiceNow stated that security updates for CVE-2026-6875 were deployed to ServiceNow-hosted instances when the patches were released. Organizations operating self-hosted ServiceNow environments are responsible for applying the updates themselves.
Deployment status
Operational priority
ServiceNow-hosted instances
Confirm vendor update status and review security advisories.
Self-hosted ServiceNow
Verify patches are installed, review logs, and validate exposed systems.
Administrative workstations
Confirm compliance and restrict privileged administration from unmanaged devices.
For many enterprises, patching is only the first step. Security teams should verify that updates were successfully deployed, review exposed instances for missing updates, and confirm that vulnerable systems are no longer running affected versions.
What the Reported Exploitation Actually Confirms
Security reporting around ServiceNow CVE-2026-6875 requires careful interpretation.
Defused reported observing in-the-wild exploitation after technical details became public. The company initially believed the observed payload differed from Searchlight Cyber’s published technique but later updated its findings, confirming that the payload matched Searchlight Cyber’s proof of concept.
ServiceNow told SecurityWeek that it found no evidence linking the reported activity to ServiceNow-hosted instances. It also urged customers that had not already done so to apply the relevant updates.
This incident primarily aligns with Hexnode UEM, while Hexnode XDR can complement endpoint investigations where deployed.
Hexnode UEM supports enterprise patch management with visibility into managed endpoints, device posture, and configuration compliance.
Compliance policies help identify managed devices that meet organizational security requirements, enabling administrators to prioritize compliant devices during remediation.
Hexnode XDR can support XDR investigation by providing visibility into suspicious endpoint activity, process execution, incidents, and login events on managed Windows devices.
Both products complement incident response but do not replace vendor patching, ServiceNow log analysis, or application-specific security reviews.
Conclusion
Reported exploitation shortly after disclosure makes CVE-2026-6875 a priority for organizations running vulnerable ServiceNow AI Platform deployments. While ServiceNow-hosted instances received vendor updates, organizations using self-hosted ServiceNow deployments should verify that patches have been successfully applied.
Beyond patching, security teams should review administrative activity, validate integrations, confirm device compliance for privileged access, and include AI-enabled enterprise platforms in ongoing exposure management.
Strengthen your endpoint readiness
Start your free trial to simplify endpoint compliance and patch visibility.
CVE-2026-6875 is a critical sandbox escape vulnerability in the ServiceNow AI Platform that could enable unauthenticated remote code execution under certain circumstances.
Who needs to install the patch?
ServiceNow stated that security updates were deployed to hosted instances, while organizations operating self-hosted deployments must apply the provided patches. Organizations operating self-hosted ServiceNow deployments must apply the relevant patches themselves.
Does reported exploitation mean every vulnerable instance has been compromised?
No. Public reporting confirms observed exploitation activity, but it does not confirm widespread compromise or attacks against every vulnerable deployment. Organizations should verify patch status and investigate their own environments accordingly.
A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.