CyberSecurity

ServiceNow Vulnerability Exploited in the Wild Just Days After Disclosure

Published

on

Critical Flaw Under Active Attack

A critical vulnerability in the ServiceNow AI platform is being exploited in the wild, just days after a patch was released. The flaw, tracked as CVE-2026-6875, is a sandbox escape issue that can allow an unauthenticated attacker to execute arbitrary code under certain conditions.

ServiceNow rolled out a security update on July 14, confirming that hosted instances had been patched. The catch? Self-hosted customers are on their own — they must install the fixes manually.

Disclosure and Immediate Exploitation

On the same day the patch was announced, cybersecurity firm Searchlight Cyber went public with technical details and a proof-of-concept. That transparency had an almost immediate consequence.

By July 18, threat intelligence firm Defused reported seeing real-world exploitation of CVE-2026-6875. Attackers were clearly leveraging the information Searchlight had released. Initially, Defused claimed the exploit reached the same outcome as Searchlight’s PoC but through a slightly different method. On Monday, however, they issued a correction: closer analysis showed the captured payload was actually identical to Searchlight’s own.

Who’s Behind the Attacks?

Defused’s correction raises an uncomfortable question. There are no other public reports of CVE-2026-6875 being exploited. One plausible explanation? The activity could be coming from within the cybersecurity industry itself — researchers scanning for vulnerable systems.

ServiceNow’s official advisory still states there’s no evidence of active exploitation, and it hasn’t been updated to reflect Defused’s findings.

Vendor Response and Patch Guidance

In a statement to SecurityWeek, a ServiceNow spokesperson said: “ServiceNow is aware of a cybersecurity company’s recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as CVE-2026-6875. Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts.”

The spokesperson added that the company has “provided updates and patches designed to address this issue” and encouraged both self-hosted and ServiceNow-hosted customers to apply the relevant patches if they haven’t already. They also offered direct assistance for customers struggling with the patch process.

A Pattern of Researcher-Driven Exploitation

This isn’t the first time ServiceNow has seen this dynamic play out. Last month, the company informed customers about an exploited vulnerability — only to later clarify that the exploitation was the work of security researchers, not malicious actors.

True threat actor exploitation of ServiceNow flaws remains rare. The CISA KEV catalog currently lists only two ServiceNow vulnerabilities, both patched back in 2024.

What Should Organizations Do Now?

The window between disclosure and exploitation is shrinking across the industry. For ServiceNow customers, the calculus is straightforward:

  • Self-hosted instances: Apply the patch immediately. There’s no vendor-managed safety net here.
  • Hosted instances: Verify that ServiceNow has applied the update to your environment. Don’t assume — confirm.
  • Monitor logs: Look for unusual activity that could indicate a sandbox escape attempt, especially if your instance hasn’t been patched yet.

The speed of this exploitation cycle is a reminder that public disclosure is a double-edged sword. It empowers defenders, but it also hands attackers a roadmap. For those running self-hosted ServiceNow, the message is clear: patch now, ask questions later. The longer you wait, the more you’re gambling with your environment’s security.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version