Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

July 26, 2026

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

July 26, 2026

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

July 25, 2026
Facebook X (Twitter) Instagram
Sunday, July 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
News

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Team-CWDBy Team-CWDJuly 26, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber.

In a post shared on X, the threat intelligence firm said it’s observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code.

Patches for the flaw were released by ServiceNow throughout June in the following versions –

  • Brazil EA and Brazil GA
  • Australia Patch 2
  • Zurich Patch 7b and Zurich Patch 9
  • Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13

Searchlight Cyber, which disclosed additional technical specifics, said it reported the issue on April 1, 2026, adding it allows a complete compromise of the ServiceNow instance as well as all connected proxy servers.

Besides rolling out a fix, ServiceNow is “enhancing instance security by severely restricting the type of code that can run in sandbox contexts,” security researcher Adam Kues noted.

Defused initially noted that the exploitation efforts target the same pre-authentication endpoint (“/assessment_thanks.do”) using HTTP POST requests, although the sandbox-escape gadget leads to the same code execution primitive by a different route documented in the proof-of-concept (PoC) exploit.

However, in a subsequent post, Defused issued a correction, stating the captured payload in fact matches that of Searchlight Cyber’s PoC.

In light of active exploitation, customers of self-hosted versions are advised to apply the fixes, if not already, to counter the threat.

Update

Following the publication of the story, a ServiceNow spokesperson told The Hacker News that there has been no exploitation observed to date.

“ServiceNow is aware of a cybersecurity company’s recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as CVE-2026-6875,” the spokesperson noted. “Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts.”

“We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so. In addition, we will continue to work directly with customers who need assistance in applying the patches.”

(The story was updated after publication to include a response from ServiceNow.)



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Next Article New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Team-CWD
  • Website

Related Posts

News

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

July 26, 2026
News

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

July 25, 2026
News

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

July 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Look out for phony verification pages spreading malware

September 14, 2025

What if your romantic AI chatbot can’t keep a secret?

November 18, 2025

Beware of threats lurking in booby-trapped PDF files

October 7, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.