ServiceNow Vulnerability Exploited Days Post-Disclosure, Cybersecurity Alert

www.news4hackers.com-servicenow-vulnerability-exploited-days-post-disclosure-cybersecurity-alert-servicenow-vulnerability-exploited-days-post-disclosure-cybersecurity-alert

Exploitation of ServiceNow Vulnerability Observed Shortly After Public Disclosure

A company representative stated, “ServiceNow is aware of a cybersecurity company’s recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as CVE-2026-6875.” The statement added that no evidence of the activity linking to ServiceNow-hosted instances had been found. The vendor urged customers to apply available patches and offered support for those requiring assistance.

A recently addressed remote code execution flaw in the ServiceNow AI platform has been detected in active cyberattacks, according to cybersecurity researchers. The vulnerability, designated CVE-2026-6875, allows an unauthenticated user to execute arbitrary code under specific conditions through a sandbox escape mechanism. ServiceNow released patches for the issue on July 14, stating that updates were automatically applied to hosted environments. Customers operating self-hosted instances were required to implement the fixes manually. On the same day, the cybersecurity firm Searchlight Cyber shared detailed analysis and exploitation methods for the flaw. Subsequently, threat intelligence provider Defused reported on July 18 that it had identified real-world exploitation of CVE-2026-6875, utilizing techniques outlined by Searchlight Cyber. Initially, Defused noted differences in the exploit’s approach compared to the proof-of-concept, but later revised its assessment. A follow-up statement confirmed that the captured payload matched Searchlight Cyber’s original method. ServiceNow’s initial advisory did not acknowledge active exploitation, and no updates have been issued to reflect the recent findings. No additional reports of exploitation have emerged, though the activity may involve cybersecurity professionals testing for vulnerable systems. ServiceNow previously alerted customers to an exploited vulnerability last month, later clarifying that the incident involved security researchers rather than malicious actors. The company’s vulnerabilities are rarely targeted by threat groups, as indicated by CISA’s Known Exploited Vulnerabilities catalog, which lists only two patched flaws from 2024. The incident highlights ongoing challenges in securing enterprise platforms, with rapid disclosure and patching efforts often outpaced by adversarial activity. Organizations are advised to prioritize timely updates and monitor for anomalous behavior linked to known vulnerabilities.



About Author

en_USEnglish