type: cve ยท created: 2026-07-22 ยท updated: 2026-07-22 ยท tags: [cve, kev, rce, sandbox-escape, ai, servicenow] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, healthcare, finance] ยท au_impact: true
CVE-2026-6875 โ ServiceNow AI Platform Sandbox Escape
CVE-2026-6875 is a critical sandbox escape vulnerability in the ServiceNow AI Platform, rated CVSS 9.5, allowing unauthenticated remote code execution. It is being actively exploited in the wild.
Status: Active Exploitation
- Discovered by: Defused Cyber researchers
- Active exploitation confirmed in July 2026
- ServiceNow fixes: Released throughout June 2026
- Mitigation: ServiceNow is restricting the type of code that can run in sandbox contexts
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-6875 |
| CVSS | 9.5 (Critical) |
| Type | Sandbox escape โ Unauthenticated Remote Code Execution |
| Product | ServiceNow AI Platform |
| Active exploitation | Confirmed |
| Fix | June 2026 (multiple patch releases) |
Australian Significance
ServiceNow is widely deployed across Australian enterprises and government agencies for IT service management and increasingly for AI-platform workloads. Organisations running ServiceNow AI Platform instances should verify patch status immediately. The active exploitation status suggests automated scanning is likely.
Mitigation
- Apply all ServiceNow security patches released in June 2026
- Review sandbox restrictions โ ServiceNow is restricting executable code types
- Monitor for unauthorised code execution in ServiceNow AI Platform instances
- Segment ServiceNow AI Platform from critical internal systems
Related Pages
- Cve 2026 50522 Sharepoint Server Rce โ Critical SharePoint RCE (CVSS 9.8)
- Rogueplanet Cve 2026 50656 โ Microsoft Defender mpengine race condition (CVSS 7.8)