Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Estée Lauder discloses data breach via Oracle E-Business flaw

    July 20, 2026

    WP2Shell Vulnerabilities: CVE-2026-60137 and CVE-2026-63030 | Blog

    July 20, 2026

    New Orleans Cops Published Policy Document Allowing Weaponized Drones

    July 20, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Critical ServiceNow code execution flaw now exploited in attacks
    News

    Critical ServiceNow code execution flaw now exploited in attacks

    adminBy adminJuly 20, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    ServiceNow

    Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.

    Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows.

    Cybersecurity company Searchlight Cyber, which found this critical vulnerability and reported it on April 1st, says that it allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks.

    image

    ServiceNow addressed the flaw across hosted instances and released CVE-2026-6875 security updates for self-hosted instances one week ago, on July 13th.

    Over the weekend, Defused security researchers confirmed that attackers have begun exploiting the vulnerability in the wild, with the first attempts being observed on Friday, days after ServiceNow issued patches.

    “We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875),” Defused warned in a Saturday tweet.

    “The payloads hit the same pre-auth sink @SLCyberSec documented (/assessment_thanks.do), but the sandbox-escape gadget reaches the same code-execution primitive by a different route than their published PoC.”

    CVE-2026-6875 exploitation
    CVE-2026-6875 exploitation (Defused)

    ServiceNow has yet to flag this security as actively abused and, in the official advisory, still states that it is “not currently aware of exploitation against ServiceNow instances.”

    However, the company advises all customers who have not already done so to secure their systems against attacks by upgrading to a patched release as soon as possible.

    A ServiceNow spokesperson was not immediately available for comment when BleepingComputer reached out to confirm Defused’s report that CVE-2026-6875 is now actively exploited.

    Last month, ServiceNow also privately disclosed a security incident in which attackers queried data from customer instances by exploiting an unauthenticated access flaw via a vulnerable API endpoint.

    In a subsequent advisory, it tied the incident to security researchers or customer-led research linked to bug bounty submissions rather than to malicious threat actors.

    ServiceNow says that its AI Platform runs more than 100 billion workflows each year and powers over 100,000 enterprise AI apps at 85% of all Fortune 500 companies.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleI got inside FIFA’s Secret World Cup Broadcast Network
    Next Article Microsoft confirms Windows Server Update Services sync delays
    admin
    • Website

    Related Posts

    News

    Estée Lauder discloses data breach via Oracle E-Business flaw

    July 20, 2026
    News

    WP2Shell Vulnerabilities: CVE-2026-60137 and CVE-2026-63030 | Blog

    July 20, 2026
    News

    New Orleans Cops Published Policy Document Allowing Weaponized Drones

    July 20, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202635 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202635 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Our Picks

    Estée Lauder discloses data breach via Oracle E-Business flaw

    July 20, 2026

    WP2Shell Vulnerabilities: CVE-2026-60137 and CVE-2026-63030 | Blog

    July 20, 2026

    New Orleans Cops Published Policy Document Allowing Weaponized Drones

    July 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.