Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GolangGhost macOS Malware Steals Chrome Secrets and MetaMask Permissions
July 22, 2026
Google Chrome Patches 12 Vulnerabilities, Fixing Browser Attack Risk
July 22, 2026
Critical ServiceNow Vulnerability Actively Exploited in the Wild
July 22, 2026
Home/CyberSecurity News/Critical ServiceNow Vulnerability Actively Exploited in the Wild
CyberSecurity News

Critical ServiceNow Vulnerability Actively Exploited in the Wild

Key Takeaways A critical pre-authentication vulnerability, CVE-2026-6875, affecting ServiceNow’s AI Platform is under active exploitation. The flaw allows unauthenticated attackers to escape...

David kimber
David kimber
July 22, 2026 3 Min Read
4 0

Key Takeaways

  • A critical pre-authentication vulnerability, CVE-2026-6875, affecting ServiceNow’s AI Platform is under active exploitation.
  • The flaw allows unauthenticated attackers to escape the script sandbox and execute arbitrary code on vulnerable instances.
  • ServiceNow has released security updates for both hosted and self-managed deployments.
  • Organizations must immediately apply patches and enable Guarded Script for enhanced protection.

Critical ServiceNow Flaw Actively Exploited in the Wild

A severe vulnerability within the ServiceNow AI Platform, identified as CVE-2026-6875, is currently being leveraged by malicious actors. This critical flaw enables unauthenticated attackers to bypass the platform’s script sandbox and execute code remotely on affected systems.

Table Of Content

  • Key Takeaways
  • Critical ServiceNow Flaw Actively Exploited in the Wild
  • Discovery and Technical Details
  • Active Exploitation Confirmed
  • ServiceNow’s Response and Mitigation
  • What You Should Do

Described as a pre-authentication sandbox escape, the vulnerability specifically targets the ServiceNow AI Platform. Its “pre-authentication” nature signifies that an attacker does not require valid credentials to initiate a compromise attempt against a susceptible instance. ServiceNow has confirmed that, under specific conditions, this issue could indeed lead to unauthenticated code execution within the platform.

Discovery and Technical Details

Security researchers at Assetnote, part of Searchlight Cyber have warned, were responsible for discovering CVE-2026-6875. They reported the vulnerability to ServiceNow on April 1, 2026. Their investigation revealed that attacker-controlled input could reach a server-side GlideRecord query path, subsequently triggering JavaScript evaluation. The vulnerable pathway reportedly involves the /assessment_thanks.do endpoint, which attackers can utilize to access a pre-authentication script execution point and exploit weaknesses in the script sandbox to achieve full code execution.

Active Exploitation Confirmed

The severity of this flaw is amplified by its active exploitation in the wild. Successful exploitation grants attackers the capability to execute code within the ServiceNow environment. Researchers from Searchlight Cyber highlighted that such access could empower attackers to extract sensitive platform data, create unauthorized administrative accounts, and potentially execute commands via configured MID Servers or proxy infrastructure.

While ServiceNow’s initial advisory indicated no awareness of active exploitation, subsequent reports from threat intelligence firm Defused said the vulnerability is being exploited, confirming that exploit attempts commenced shortly after the public disclosure of the vulnerability.

ServiceNow’s Response and Mitigation

ServiceNow has promptly released security updates to address this vulnerability. The company has deployed these updates to its hosted instances and made relevant patches available for customers and partners managing self-hosted deployments. Organizations operating self-managed ServiceNow instances are strongly advised to apply the latest security update or upgrade to a patched release immediately. Furthermore, enabling Guarded Script is recommended as an additional mitigation measure against sandbox escape attacks.

Guarded Script provides an extra layer of protection by limiting the types of JavaScript expressions that can be executed in sandboxed contexts. This feature restricts constructs such as variable declarations, control flow statements, function declarations, assignments, and multiple statements, thereby reducing the attack surface for sandbox escapes.

What You Should Do

  • Apply Patches Immediately: For self-hosted ServiceNow deployments, apply the latest security updates or upgrade to a patched version without delay. Hosted instances should already be updated by ServiceNow.
  • Enable Guarded Script: Implement Guarded Script to enhance protection against sandbox escape attacks by restricting JavaScript execution capabilities in sandboxed environments.
  • Monitor for Suspicious Activity: Review logs for any unusual requests targeting the /assessment_thanks.do endpoint and investigate suspicious parameters associated with sysparm_assessable_type.
  • Watch for Anomalous Behavior: Monitor for unexpected administrative account creations, abnormal script activity, and any suspicious actions involving MID Servers.
  • Review ServiceNow Advisories: Stay informed by regularly checking ServiceNow’s official security advisories for the latest information and recommended actions.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

OpenAI GPT Agents Exploit Zero-Days and Hacked Hugging Face Servers

Next Post

Google Chrome Patches 12 Vulnerabilities, Fixing Browser Attack Risk

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Qilin Ransomware Claims 1,358 Victims, Global Attacks Soar
July 21, 2026
Hackers Hijack Government Websites to Deliver Malware via Trusted Links
July 21, 2026
New Crypter Evades EDR and Deletes Malware From Disk
July 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us