Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-22 ยท updated: 2026-07-22 ยท tags: [cve, kev, rce, sandbox-escape, ai, servicenow] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, healthcare, finance] ยท au_impact: true

CVE-2026-6875 โ€” ServiceNow AI Platform Sandbox Escape

CVE-2026-6875 is a critical sandbox escape vulnerability in the ServiceNow AI Platform, rated CVSS 9.5, allowing unauthenticated remote code execution. It is being actively exploited in the wild.

Status: Active Exploitation

  • Discovered by: Defused Cyber researchers
  • Active exploitation confirmed in July 2026
  • ServiceNow fixes: Released throughout June 2026
  • Mitigation: ServiceNow is restricting the type of code that can run in sandbox contexts

Vulnerability Details

Attribute Detail
CVE CVE-2026-6875
CVSS 9.5 (Critical)
Type Sandbox escape โ†’ Unauthenticated Remote Code Execution
Product ServiceNow AI Platform
Active exploitation Confirmed
Fix June 2026 (multiple patch releases)

Australian Significance

ServiceNow is widely deployed across Australian enterprises and government agencies for IT service management and increasingly for AI-platform workloads. Organisations running ServiceNow AI Platform instances should verify patch status immediately. The active exploitation status suggests automated scanning is likely.

Mitigation

  1. Apply all ServiceNow security patches released in June 2026
  2. Review sandbox restrictions โ€” ServiceNow is restricting executable code types
  3. Monitor for unauthorised code execution in ServiceNow AI Platform instances
  4. Segment ServiceNow AI Platform from critical internal systems

Related Pages