HackMyIP
← Back to News
2026-07-21 The Hacker News

Critical ServiceNow AI Sandbox Escape Flaw Actively Exploited for RCE

VulnerabilityAI SecurityCloud Security

Threat actors are weaponizing a severe sandbox escape vulnerability in the ServiceNow AI Platform, enabling unauthenticated attackers to execute arbitrary code on vulnerable instances. Tracked as CVE-2026-6875 with a CVSS score of 9.5, the flaw grants complete compromise of the ServiceNow instance along with every connected proxy server, according to threat intelligence firm Defused Cyber, which first observed in-the-wild exploitation targeting the pre-authentication endpoint /assessment_thanks.do via HTTP POST requests.

Searchlight Cyber, the security firm that originally disclosed the vulnerability after reporting it on April 1, 2026, confirmed the captured payload matches its proof-of-concept exploit. The sandbox-escape technique ultimately provides the same code execution primitive through a different route than the initially observed endpoint. Security researcher Adam Kues noted that beyond shipping a fix, ServiceNow is "enhancing instance security by severely restricting the type of code that can run in sandbox contexts" to prevent recurrence.

Patches were distributed throughout June 2026 across multiple release branches, including Brazil EA and Brazil GA, Australia Patch 2, Zurich Patch 7b and Patch 9, as well as Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13. Defused later corrected its initial assessment, clarifying that the captured exploit payload aligned with Searchlight Cyber's publicly documented PoC rather than representing an independent attack chain. Organizations running self-hosted ServiceNow deployments should audit their instances immediately and verify TLS configurations using an SSL/TLS checker to confirm secure transport settings on affected endpoints.

Given the critical severity and confirmed active exploitation, any organization still running unpatched ServiceNow instances faces imminent risk of remote takeover. Security teams are urged to scan their externally exposed infrastructure with a port scanner to identify any ServiceNow instances reachable from the internet, and run a comprehensive privacy checkup across connected systems to detect indicators of compromise tied to this campaign.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →