Vulnerability  ·  2026-07-22

ServiceNow AI Platform Pre-Auth Sandbox-Escape RCE Actively Exploited in the Wild

VulnerabilityHigh impactGlobalCVE-2026-6875
ServiceNow patched a critical pre-auth RCE/sandbox-escape flaw in its AI Platform on 2026-07-14. Threat intelligence firm Defused reported on 2026-07-18 that it observed in-the-wild exploitation of the vulnerability, with attackers changing tactics from the original Searchlight Cyber proof-of-concept in response to vendor patches and defenses.
The exploitation targets the sandbox isolation layer meant to safely contain AI-driven code execution within an enterprise AI platform — confirming that AI execution sandboxes are now a primary target for real-world attackers, and that sandbox-escape techniques against AI platforms are being actively weaponized rather than remaining theoretical.
A pre-authentication sandbox-escape vulnerability in the ServiceNow AI Platform allows an unauthenticated remote attacker to break out of the platform's execution sandbox and achieve arbitrary remote code execution under certain circumstances.
ServiceNow AI Platform (self-hosted instances; patched hosted instances)
Apply the ServiceNow security update released 2026-07-14 to all self-hosted instances immediately; hosted instances were already patched by the vendor.
SecurityWeek — Exploitation of ServiceNow Vulnerability Seen Days After DisclosureCSO Online — ServiceNow's sandbox escape RCE hole now exploited in the wild
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →