ServiceNow CVE-2026-6875 RCE: Sandbox Escape Exploited

ServiceNow CVE-2026-6875 RCE is now being actively exploited: a critical, unauthenticated sandbox-escape vulnerability in the ServiceNow AI Platform is under attack barely a week after the vendor shipped a fix, and ServiceNow’s own advisory has not yet caught up with independent confirmation of the exploitation.
What Happened
ServiceNow CVE-2026-6875 RCE traces back to a sandbox-escape flaw in the ServiceNow AI Platform (formerly the Now Platform) that Searchlight Cyber discovered and responsibly disclosed to the vendor on April 1. The bug carries a CVSS 4.0 base score of 9.5 and allows an unauthenticated attacker to send crafted requests to the pre-auth endpoint /assessment_thanks.do and escape the platform’s sandbox to execute code remotely, in high-complexity attack scenarios.
ServiceNow shipped the fix to its hosted (vendor-managed) instances automatically and released patches for self-hosted customers and partners on July 13 (fixed releases: Australia Patch 2, Brazil EA/GA, Zurich Patch 7b and 9, Yokohama Patch 12 Hot Fix 1b and Patch 13). One week later, over the weekend of July 17–18, threat-intelligence firm Defused confirmed in-the-wild exploitation: the payloads hit the same pre-auth sink Searchlight documented, but reach code execution through a different sandbox-escape gadget than the one in the published proof-of-concept.
As of publication, ServiceNow’s own security advisory still states the company is “not currently aware of exploitation against ServiceNow instances” — a gap between vendor messaging and independent researcher confirmation that IT teams should not wait out. The vulnerability is not yet listed in CISA’s Known Exploited Vulnerabilities catalog.
Why It Matters
ServiceNow states its AI Platform runs more than 100 billion workflows a year and powers over 100,000 enterprise AI apps at 85% of Fortune 500 companies — a scale that makes this one of the largest single attack surfaces disclosed this year. In the DACH Mittelstand, ServiceNow is a common backbone for IT service management, HR case management and customer service workflows, often holding employee and customer data subject to NIS2 and GDPR obligations. Because the flaw is unauthenticated and pre-auth, any internet-facing, unpatched instance is exposed without an attacker needing valid credentials — and the vendor’s own “no known exploitation” language creates a false sense of safety for teams relying on official advisories rather than independent telemetry.
What You Should Do Now
- Immediate: Upgrade self-hosted ServiceNow instances to a fixed release now — Australia Patch 2, Brazil EA/GA, Zurich Patch 7b/9, or Yokohama Patch 12 Hot Fix 1b/13, per ServiceNow KB3137947.
- Verify: Confirm hosted (ServiceNow-managed) instances have received the automatic fix by checking your instance’s patch status against KB3137947 in the Now Support (HI) portal.
- Mitigate: If immediate patching is not possible, restrict or monitor external access to the
/assessment_thanks.doendpoint at the WAF or reverse-proxy layer as a stopgap. - Monitor: Review web server and WAF logs for anomalous requests to
/assessment_thanks.dofrom unrecognized source IPs — treat any hit as a possible compromise indicator, not merely a scan.
DIESEC Perspective
We have seen the same pattern play out with SharePoint and FortiSandbox earlier this year: a vendor advisory that has not caught up with independent researcher confirmation creates a dangerous assumption that “no news is good news.” Treat this one as exploited until your own logs say otherwise.
Not sure whether your ServiceNow instance is running a patched release or has already been probed against this endpoint? Contact DIESEC for a rapid patch verification and exposure check.
Sources: BleepingComputer | NVD
Published: 2026-07-21 | Category: Vulnerabilities & Patches | ~4 min read

