ServiceNow RCE exploited days after PoC disclosure
Days after a PoC for CVE-2026-6875 was published, Defused reported in-the-wild exploitation and later confirmed the captured payload matched the PoC.
Threat intelligence firm Defused reported on July 18 that it had observed exploitation in the wild of CVE-2026-6875, a remote code execution vulnerability in ServiceNow that can allow a sandbox escape under specific conditions. Defused later corrected its analysis, concluding the captured payload was identical to a previously published proof-of-concept.
Security firm Searchlight Cyber published technical details and a proof-of-concept for CVE-2026-6875 on July 14. On the same day, ServiceNow deployed a security update to instances it operates; customers running self-hosted ServiceNow must install the patch themselves.
The flaw is described as a sandbox escape that can permit an unauthenticated attacker to execute arbitrary code in certain workflows. ServiceNow assigned the identifier CVE-2026-6875 and classified it as a remote code execution issue enabling sandbox breakout in specific configurations.
Defused initially reported that the exploit reached the same outcome as Searchlight’s demonstration through a slightly different technique. After further analysis, Defused issued a correction stating the captured payload matched Searchlight’s proof-of-concept.
ServiceNow’s statement reads: “Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts. We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so. In addition, we will continue to work directly with customers who need assistance in applying the patches.”
ServiceNow’s initial advisory reported no knowledge of active exploitation; that advisory has not been updated to reflect Defused’s findings. Security teams commonly test public proof-of-concepts against live systems, which can produce early activity that resembles malicious scanning or testing.
CISA’s Known Exploited Vulnerabilities catalog currently lists two ServiceNow flaws, both patched in 2024.
Organizations operating self-hosted ServiceNow instances should verify that patches addressing CVE-2026-6875 are installed. ServiceNow has offered direct assistance to customers that need help applying the fixes.








