ServiceNow RCE Flaw Exploited Within Days of Patch — But Who's Actually Behind It?
A critical remote code execution vulnerability in ServiceNow's AI platform has been spotted being used in the wild, just four days after patches dropped. Whether that counts as a genuine attack campaign is, frankly, still up for debate.
The flaw, CVE-2026-6875, is a sandbox escape bug that allows an unauthenticated attacker to run arbitrary code under certain conditions. ServiceNow pushed patches on July 14 and automatically deployed them to hosted instances. Self-hosted customers, as is tradition, are on their own.
The same day patches landed, security firm Searchlight Cyber published a full technical writeup and a working proof-of-concept. Threat intelligence outfit Defused then reported on July 18 that it had observed active exploitation in the wild, apparently based on Searchlight's public research.
There's a wrinkle, though. Defused initially claimed the observed payload differed slightly from Searchlight's PoC. They later walked that back, admitting on closer inspection that the captured payload was actually identical to Searchlight's own. So either someone copied the exploit verbatim from a public writeup, or the 'attacker' was Searchlight itself, or someone else in the security industry poking around. None of those scenarios exactly screams sophisticated threat actor.
ServiceNow's official position is carefully worded. A spokesperson told SecurityWeek the company is aware of the reported exploitation activity but has found no evidence it affected any ServiceNow-hosted instances. They're encouraging all customers, hosted or otherwise, to apply patches if they haven't already.
The vendor's original advisory claimed no knowledge of active exploitation and hadn't been updated to reflect the new reports at time of writing.
This pattern will feel familiar. Last month ServiceNow alerted customers about an exploited vulnerability, only to later clarify the activity had been carried out by security researchers rather than actual attackers. That kind of false alarm erodes trust in threat reporting generally.
For context, ServiceNow vulnerabilities don't get weaponised all that often. CISA's Known Exploited Vulnerabilities catalogue lists just two ServiceNow flaws, both patched back in 2024.
Bottom line: patch your self-hosted instances, and treat the 'active exploitation' label here with appropriate caution until more credible attribution emerges.