Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows.
Cybersecurity company Searchlight Cyber, which found this critical vulnerability and reported it on April 1st, says that it allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks.
ServiceNow addressed the flaw across hosted instances and released CVE-2026-6875 security updates for self-hosted instances one week ago, on July 13th.
Over the weekend, Defused security researchers confirmed that attackers have begun exploiting the vulnerability in the wild, with the first attempts being observed on Friday, days after ServiceNow issued patches.
“We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875),” Defused warned in a Saturday tweet.
“The payloads hit the same pre-auth sink @SLCyberSec documented (/assessment_thanks.do), but the sandbox-escape gadget reaches the same code-execution primitive by a different route than their published PoC.”
ServiceNow has yet to flag this security as actively abused and, in the official advisory, still states that it is “not currently aware of exploitation against ServiceNow instances.”
However, the company advises all customers who have not already done so to secure their systems against attacks by upgrading to a patched release as soon as possible.
A ServiceNow spokesperson was not immediately available for comment when BleepingComputer reached out to confirm Defused’s report that CVE-2026-6875 is now actively exploited.
Last month, ServiceNow also privately disclosed a security incident in which attackers queried data from customer instances by exploiting an unauthenticated access flaw via a vulnerable API endpoint.
In a subsequent advisory, it tied the incident to security researchers or customer-led research linked to bug bounty submissions rather than to malicious threat actors.
ServiceNow says that its AI Platform runs more than 100 billion workflows each year and powers over 100,000 enterprise AI apps at 85% of all Fortune 500 companies.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
You must be logged in to post a comment Login