A severe remote code execution vulnerability in the ServiceNow AI platform, known as CVE-2026-6875, is being actively exploited shortly after its patch was released. This vulnerability, which allows unauthorized attackers to execute arbitrary code by exploiting a sandbox escape issue, was addressed by ServiceNow on July 14 with a security update for hosted instances. However, self-hosted customers need to apply the patch manually.

On the same day, Searchlight Cyber revealed technical details and demonstrated how the vulnerability could be exploited, which inadvertently led to its active exploitation in the wild. Threat intelligence firm Defused reported on July 18 that the exploit was being used in the wild, initially noting a different method from the proof-of-concept but later confirming it was identical to Searchlight Cyber’s findings.

Despite these developments, ServiceNow has stated that it has not observed any evidence of this exploitation affecting the instances it hosts. The company urges both self-hosted and ServiceNow-hosted customers to apply the patches if they have not yet done so and continues to offer support for those needing help.

While there are no other reports of exploitation, the activity may be attributed to security researchers searching for vulnerable systems rather than malicious attackers. Historically, ServiceNow vulnerabilities have not been frequently exploited by threat actors, as reflected in the CISA’s Known Exploited Vulnerabilities catalog.