← back

CVE-2026-6875

EPSS 24.5%
hype MIXED · 52 hack

Real vuln with patches; exploitation claims unverified vs. vendor denial; mixed signal.

What: Unauthenticated remote code execution in ServiceNow AI Platform via sandbox escape (CVSS 9.5). Affects self-hosted and SaaS instances.

Why it matters: Social posts claim active exploitation since July 17, but ServiceNow's official advisory (July 13) states "not currently aware of exploitation." No KEV listing. EPSS is extremely low (0.40th percentile). Patches deployed immediately to hosted instances; self-hosted updates available. Credibility gap: threat intelligence vendor cited ("Defused") but advisory from vendor contradicts exploitation claims.

Where it's seen: Bluesky amplification of "critical sandbox escape RCE" narratives, with posts referencing Defused and HackerNews; some claim July 17 in-the-wild activity despite no vendor confirmation. No PoC code visible.

RISK: HIGH — Unauthenticated RCE in widely-deployed SaaS/self-hosted platform, high CVSS, but no confirmed exploitation.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 7/21/2026, 9:23:08 AM

Description

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Weaknesses