CuraSec

Act archived

ServiceNow AI Platform CVE-2026-6875 Unauthenticated RCE Actively Exploited

2026-07-21 12:43 UTC · The Hacker News · read the source ↗ #servicenow#rce#active-exploitation
  • Engineer — Act: Public PoC exists and in-the-wild exploitation is reported for this unauthenticated sandbox-escape RCE (CVSS 9.5) in the ServiceNow AI Platform. Confirm your ServiceNow instance has the available patch applied via the admin console, and audit platform logs for anomalous code execution since the disclosure date.
  • SOC/IR — Act: Active exploitation of unauthenticated RCE on a widely deployed enterprise ITSM platform creates immediate detection work. Hunt for anomalous outbound connections, unusual process spawning, or lateral movement originating from ServiceNow infrastructure since the vulnerability was disclosed, and tune EDR/SIEM for post-exploitation behavior on hosts that ServiceNow agents touch.
  • Leader — Act: A critical unauthenticated RCE in ServiceNow with confirmed in-the-wild exploitation could expose ITSM data and integrated systems. This week, confirm with your ServiceNow admin that the patch is applied to your instance and assess whether any sensitive data (HR, IT credentials, integrations) in the platform warrants a precautionary leadership or customer notification.
  • Signals: CVE-2026-6875 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.