Jul 21
/
Latest News
ServiceNow AI Platform Flaw Now Under Active Exploitation
Threat actors are actively exploiting a critical vulnerability in the ServiceNow AI Platform, according to Defused Cyber, which reported seeing real‑world attacks targeting CVE‑2026‑6875. The flaw, rated 9.5 on the CVSS scale, is a sandbox‑escape issue that allows an unauthenticated attacker to run arbitrary code and fully compromise a ServiceNow instance along with connected proxy servers. ServiceNow released patches throughout June across its Brazil, Australia, Zurich, and Yokohama versions.
Searchlight Cyber, which disclosed additional technical details, said it first reported the issue on April 1 and confirmed that the vulnerability enables complete takeover of affected systems. ServiceNow has responded by tightening sandbox restrictions to limit what code can execute in those environments.
Defused initially believed attackers were using a different path than the proof‑of‑concept exploit, but later corrected its assessment, saying the captured payload matches Searchlight Cyber’s PoC. The exploitation attempts target the same pre‑authentication endpoint, “/assessment_thanks.do,” using HTTP POST requests.
With exploitation now underway, organizations running self‑hosted ServiceNow instances are urged to apply the available patches immediately to mitigate the risk.
Searchlight Cyber, which disclosed additional technical details, said it first reported the issue on April 1 and confirmed that the vulnerability enables complete takeover of affected systems. ServiceNow has responded by tightening sandbox restrictions to limit what code can execute in those environments.
Defused initially believed attackers were using a different path than the proof‑of‑concept exploit, but later corrected its assessment, saying the captured payload matches Searchlight Cyber’s PoC. The exploitation attempts target the same pre‑authentication endpoint, “/assessment_thanks.do,” using HTTP POST requests.
With exploitation now underway, organizations running self‑hosted ServiceNow instances are urged to apply the available patches immediately to mitigate the risk.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.