ServiceNow patched this in April. attackers are exploiting it now with a different trick

The published proof-of-concept and the real attacks hit the same endpoint through two different doors — which is why patching alone didn't close…

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-6875 (CVSSv4 9.5) lets an unauthenticated attacker escape ServiceNow's script sandbox and execute code remotely on AI Platform instances.

The short version

Searchlight Cyber reported it privately on April 1, 2026; ServiceNow patched hosted/cloud instances directly that same month.

The short version

Self-hosted customers didn't get the patch, or the public disclosure, until July 13 — roughly a three-month gap.

The short version

Active exploitation began around July 17–18, confirmed by researchers at Defused, using a sandbox-escape route different from the published PoC.

The short version

The vulnerable path is the unauthenticated endpoint /assessment_thanks.do, via the sysparm_assessable_type parameter.

If your detection is tuned to the public PoC, you may be blind

Signature or WAF rules written against Searchlight Cyber's published exploit chain won't necessarily catch the version attackers are actually using — they reach the same code-execution primitive…

Aliteq

Read the full story

ServiceNow patched this in April. attackers are exploiting it now with a different trick

Read the full story on Aliteq