CVE-2026-6875

High PUBLISHED

Sandbox Escape in ServiceNow AI Platform

ServiceNow · ServiceNow AI Platform

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.5 Critical EPSS 0.5%

At a Glance

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

CVE Published
Jul 13, 2026
Exploitation Reported
Jul 18, 2026
CVSS
9.5 Critical
EPSS
0.5%
Remote No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
ServiceNow
ServiceNow AI Platform

0 to < Australia Patch 2

Affected
ServiceNow
ServiceNow AI Platform

0 to < Yokohama Patch 12 Hot Fix 1b

Affected
ServiceNow
ServiceNow AI Platform

0 to < Yokohama Patch 13

Affected
ServiceNow
ServiceNow AI Platform

0 to < Zurich Patch 7b

Affected
ServiceNow
ServiceNow AI Platform

0 to < Zurich Patch 9

Affected
ServiceNow
ServiceNow AI Platform

0 to < Brazil EA

Affected
ServiceNow
ServiceNow AI Platform

0 to < Brazil GA

Affected

CVE References

  • support.servicenow.com/kb support.servicenow.com · CVE Record https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=...

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.