{"id":1893,"date":"2026-07-21T10:26:27","date_gmt":"2026-07-21T10:26:27","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1893"},"modified":"2026-07-21T10:26:27","modified_gmt":"2026-07-21T10:26:27","slug":"critical-servicenow-ai-platform-flaw-exploited-for-unauthenticated-code-execution","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1893","title":{"rendered":"Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 21, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Artificial Intelligence<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjAYYV6u5s-uKU-FXeqsoZ9Bk7nvzW1gPYVuoykmnuzLBQCK0jvX7rAO12mK5FVX06ovTJHZLUUXDkFmYk88oyKdFSYByRPSL5MUuAqikrTIVEpVzOcR9j4Rn0Fmje7-VwBAO09Yl8Y4cTUVNFwTXf2FV2c9C8oyNi5coAMCMLn5WF5Fbqtyt-tDZ3MVsO0\/s1700-e365\/servicenow.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to <a href=\"https:\/\/x.com\/defusedcyber\/status\/2078418391321219448\" target=\"_blank\">Defused Cyber<\/a>.<\/p>\n<p>In a post shared on X, the threat intelligence firm said it&#8217;s observing in-the-wild exploitation of <strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-6875\" target=\"_blank\">CVE-2026-6875<\/a><\/strong> (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code.<\/p>\n<p>Patches for the flaw were <a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB3137947\" target=\"_blank\">released<\/a> by ServiceNow throughout June in the following versions &#8211;<\/p>\n<ul>\n<li>Brazil EA and Brazil GA<\/li>\n<li>Australia Patch 2<\/li>\n<li>Zurich Patch 7b and Zurich Patch 9<\/li>\n<li>Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiBxLQDy7VdLze43eMmpRllTXaPKPfB_veNUxQlqIu3-68GBJtegkhDGCqtaiSymOQviROdxln1FSd4zdMp5Jv9jeF1xQxLPc9uo9H7zW2nWHNax0wT0Y8JRj-zyUfbaCLqhxSfQT2sCfhWMBPL6UVgsh5RYVNVxwus_mW_BY9Ptwz3z7iF0_LWOnte-gqg\/s1600\/sy-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Searchlight Cyber, which disclosed additional technical specifics, said it reported the issue on April 1, 2026, adding it allows a complete compromise of the ServiceNow instance as well as all connected proxy servers.<\/p>\n<p>Besides rolling out a fix, ServiceNow is \u00abenhancing instance security by severely restricting the type of code that can run in sandbox contexts,\u00bb security researcher Adam Kues <a href=\"https:\/\/slcyber.io\/research-center\/smashing-the-servicenow-sandbox-pre-authentication-rce\/\" target=\"_blank\">noted<\/a>.<\/p>\n<p>According to Defused, the exploitation efforts target the same pre-authentication endpoint (\u00ab\/assessment_thanks.do\u00bb) using HTTP POST requests, although the sandbox-escape gadget leads to the same code execution primitive by a different route documented in the proof-of-concept (PoC) exploit.<\/p>\n<p>In light of active exploitation, customers of self-hosted versions are advised to apply the fixes, if not already, to counter the threat.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 21, 2026Vulnerability \/ Artificial Intelligence Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1894,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[10,58,13,128,70,527,1989,725],"class_list":["post-1893","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-code","tag-critical","tag-execution","tag-exploited","tag-flaw","tag-platform","tag-servicenow","tag-unauthenticated"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1893","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1893"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1893\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1894"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1893"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1893"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1893"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}