Vulnerabilities & Exploits · Zero-Day Exploit
Lagging ServiceNow Instances Stay Exposed After Patch Rollout The risk shifted from a vendor fix notice to live exposure on any ServiceNow AI Platform instance that has not yet taken the update. Hosted tenants were already updated, but unpatched or slow-moving customer-managed deployments remain reachable for unauthenticated code execution.
Defused says attackers are now exploiting CVE-2026-6875 in the wild. That turns the patch into a dividing line: the hosted estate is covered, but self-hosted and partner-managed instances stay at risk until the fix lands there.
For operators, the real question is no longer whether ServiceNow shipped a fix. It is whether the instance they control is still running the vulnerable code.
6 sources · Jul 21
NVD KEV
EPSS 78% (100th percentile).
Timeline Sources Jul 21 SecurityWeek
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution.
original Jul 21 The Hacker News
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Attackers exploit CVE-2026-6875 in ServiceNow AI Platform, a pre-auth sandbox escape that could compromise instances and connected proxy servers.
original Jul 21 CSO Online
ServiceNow’s sandbox escape RCE hole now exploited in the wild
But the concern goes beyond the now-patched hole’s exploitation and focuses on the lack of security surrounding any sandbox in the AI era.
original Part of the PlainSec briefing for 2026-07-16
Every edition of this story: Lagging ServiceNow Instances Stay Exposed After Patch Rollout
More from today
Vulnerabilities & Exploits · Zero-Day Exploit
Lagging ServiceNow Instances Stay Exposed After Patch Rollout The risk shifted from a vendor fix notice to live exposure on any ServiceNow AI Platform instance that has not yet taken the update. Hosted tenants were already updated, but unpatched or slow-moving customer-managed deployments remain reachable for unauthenticated code execution.
Defused says attackers are now exploiting CVE-2026-6875 in the wild. That turns the patch into a dividing line: the hosted estate is covered, but self-hosted and partner-managed instances stay at risk until the fix lands there.
For operators, the real question is no longer whether ServiceNow shipped a fix. It is whether the instance they control is still running the vulnerable code.
6 sources · Jul 21
NVD KEV
EPSS 78% (100th percentile).
Timeline Sources Jul 21 SecurityWeek
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution.
original Jul 21 The Hacker News
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Attackers exploit CVE-2026-6875 in ServiceNow AI Platform, a pre-auth sandbox escape that could compromise instances and connected proxy servers.
original Jul 21 CSO Online
ServiceNow’s sandbox escape RCE hole now exploited in the wild
But the concern goes beyond the now-patched hole’s exploitation and focuses on the lack of security surrounding any sandbox in the AI era.
original Part of the PlainSec briefing for 2026-07-16
Every edition of this story: Lagging ServiceNow Instances Stay Exposed After Patch Rollout
More from today