CVE-2026-6875
published 2026-07-13CVE-2026-6875: ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an…
PriorityP190critical9.5CVSS 4.0
AVNACHATNPRNUINVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
24.49%
97.6th percentile
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform.
ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners.
Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances.
We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| servicenow | servicenow_ai_platform | < Australia Patch 2 | Australia Patch 2 |
| servicenow | servicenow_ai_platform | < Yokohama Patch 12 Hot Fix 1b | Yokohama Patch 12 Hot Fix 1b |
| servicenow | servicenow_ai_platform | < Yokohama Patch 13 | Yokohama Patch 13 |
| servicenow | servicenow_ai_platform | < Zurich Patch 7b | Zurich Patch 7b |
| servicenow | servicenow_ai_platform | < Zurich Patch 9 | Zurich Patch 9 |
| servicenow | servicenow_ai_platform | < Brazil EA | Brazil EA |
| servicenow | servicenow_ai_platform | < Brazil GA | Brazil GA |
CVSS provenance
nvdv4.09.5CRITICALCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.5CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
ServiceNow prior Brazil EA/Brazil GA AI Platform Remote Code Execution
vuldb·2026-07-13·CVSS 9.5
CVE-2026-6875 [CRITICAL] ServiceNow prior Brazil EA/Brazil GA AI Platform Remote Code Execution
A vulnerability was found in ServiceNow and classified as critical. This affects an unknown function of the component AI Platform. The manipulation results in Remote Code Execution.
This vulnerability is cataloged as CVE-2026-6875. The attack may be launched remotely. There is no exploit available.
GHSA
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform.
ghsa_unreviewed·2026-07-13
CVE-2026-6875 [CRITICAL] CWE-94 ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform.
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform.
ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners.
Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances.
We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not alrea
VulnCheck
Improper Control of Generation of Code ('Code Injection')
vulncheck·2026·CVSS 9.5
CVE-2026-6875 [CRITICAL] Improper Control of Generation of Code ('Code Injection')
Improper Control of Generation of Code ('Code Injection')
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform.
ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners.
Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances.
We recommend customers promptly apply appropriate upd
No detection rules found.
Nuclei
ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE
nuclei·CVSS 9.5
CVE-2026-6875 [CRITICAL] ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE
ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE
ServiceNow AI Platform (Brazil, Australia, Zurich, and Yokohama releases before patching) contains a pre-authentication remote code execution vulnerability. The /assessment_thanks.do endpoint passes the sysparm_assessable_type parameter into GlideRecord's addQuery(), which evaluates "javascript:" prefixed values as JavaScript in a restricted script sandbox. A sandbox escape gadget using Object.defineProperty and Class.create.constructor chains through the gs.include('ItemViewElementsProvider') path to invoke Function(code)(), bypassing the sandbox and executing arbitrary GlideController code. Actively exploited in the wild since July 2026.
Template:
id: CVE-2026-6875
info:
name: ServiceNow AI Platform - Pre-Auth JavaScript
Hackernews
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
blogs_hackernews·2026-07-21·CVSS 9.5
CVE-2026-6875 [CRITICAL] Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber .
In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code.
Patches for the flaw were released by ServiceNow throughout June in the following versions -
Brazil EA and Brazil GA
Australia Patch 2
Zurich Patch 7b and Zurich Patch 9
Yokoham
Hackernews
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
blogs_hackernews·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.
Here is the full recap of what broke, what was exploited, and what needs attention now.
## ⚡ Threat of the Week
New wp2shell WordPress Core Flaw Lets Unauthe
2026-07-13
Published
Exploited in the wild