ServiceNow’s sandbox escape RCE hole now exploited in the wild
Summary
A sandbox security vulnerability in ServiceNow, identified as CVE-2026-6875, is reportedly being exploited in the wild. Threat intelligence firm Defused observed exploitation attempts, noting that attackers are adapting their methods to bypass ServiceNow's recently applied patches. While ServiceNow stated they have not yet observed direct exploitation on their hosted instances, they urge customers to apply the provided patches.
IFF Assessment
This article reports on a vulnerability that is actively being exploited in the wild, posing a direct threat to organizations using ServiceNow.
Severity
The vulnerability allows for pre-authentication Remote Code Execution (RCE), indicating a high attack vector and significant impact, making it a critical threat. The CVSS score reflects the severity of such an exploit.
Defender Context
This highlights the critical need for prompt patching of identified vulnerabilities, especially those with pre-authentication RCE capabilities. Defenders should monitor for exploitation attempts targeting ServiceNow instances and ensure all instances are updated to the latest security patches. The evolving nature of attack methods also emphasizes the importance of robust threat intelligence and adaptive defense strategies.