CVE Tools

CVE-2026-6875

Sandbox Escape in ServiceNow AI Platform

No known exploitation. EPSS puts it in the 72nd percentile. No fix published yet.

Published Updated Sources: CVE.org, NVD

What to do

No fixed build or workaround is published yet. Limit exposure and watch for a patch.

Steps

Written by AI from the record
  1. Check whether your ServiceNow AI Platform is on a patched release (compare your currently installed patch level against the fixed versions below: Australia Patch 2, Yokohama Patch 12 Hot Fix 1b, Yokohama Patch 13, Zurich Patch 7b, Zurich Patch 9, Brazil EA, Brazil GA).
  2. If you are not on one of those fixed releases, schedule an urgent update/upgrade to the matching fixed version for your region.
  3. After updating, verify the instance reports as updated successfully and that any recent attempts against the /assessment_thanks.do endpoint are not recurring.
  4. Search your logs and alerts for suspicious requests to the /assessment_thanks.do endpoint and signs of unexpected process/code execution, and escalate any findings to your ServiceNow administrator/vendor immediately.

What it is

From the CVE record

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

In plain language

Written by AI from the record

CVE-2026-6875 is a ServiceNow AI Platform flaw that lets outsiders run code on your system without logging in, and it’s already being exploited—so you should act immediately if you use this product.

CVE-2026-6875 is an unauthenticated remote code execution (RCE) via sandbox escape in the ServiceNow AI Platform; attackers can reach a vulnerable network endpoint to trigger code execution, and exploitation in the wild has been reported.

If you're affected

  • Full server compromise risk
  • Service disruption and downtime
  • Data theft or exposure
  • Ransomware risk

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS72nd
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

1.4% chance of exploitation activity in the next 30 days, which ranks it in the 72nd percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Attention now

Rising.

Lifecycle

14 events over 73 days, from the signal feeds we watch.

  1. EPSS band changehigh → lowepss band change
  2. EPSS band changemoderate → highepss band change
  3. EPSS band changelow → moderateanalysis published
  4. EPSS band change0 → moderateepss band change
  5. Nuclei check added
  6. OpenVAS check added

Affected products

Technical detail

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for ServiceNow AI Platform, not every advisory.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store