Corroborated exploitation of CVE-2026-6875 in ServiceNow AI Platform days after disclosure: unauthenticated RCE via sandbox escape. Apply the vendor patch on affected instances.Cyber Resilience desk
Sources (2)
What this means for you — CISO:Confirm which ServiceNow instances run the AI Platform and that CVE-2026-6875 is patched; exploitation is active, so check logs for sandbox-escape indicators now.
What this means for you — Lean IT orgs:If you use ServiceNow, it's likely managed by a vendor or MSP — ask them directly whether CVE-2026-6875 is patched; you probably don't administer this yourself.
What this means for you — MSP:Inventory every client tenant running ServiceNow AI Platform, verify patch status against CVE-2026-6875 across the board, and treat unpatched instances as urgent given confirmed in-the-wild exploitation.
What this means for you — Researcher:A sandbox-escape flaw reaching unauthenticated RCE within days of disclosure is worth dissecting for the escape technique and exploitation timeline.