Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4692 articles · 177690 vulns · 37/41 feeds (7d)
← Back to list
9.5
CVE-2026-6875KEVEXPLOITEDPATCHED
servicenow · ai platform

Sandbox Escape in ServiceNow AI Platform

Description

A remote, anonymous attacker can exploit a vulnerability in the ServiceNow AI Platform to execute arbitrary code.

Affected Products

VendorProductVersions
servicenowai platform0, 0, 0, 0, 0, 0, 0, Brazil EA, Brazil GA, Australia Patch 2, Zurich Patch 7b, Zurich Patch 9, Yokohama Patch 12 Hot Fix 1b, Yokohama Patch 13

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
servicenowai platformcert_advisory90%

References

  • https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3137947

Related News (8 articles)

Tier D
SecurityWeek2h ago
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
→ No new info (linked only)
Tier D
The Hacker News4h ago
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
→ No new info (linked only)
Tier D
Help Net Security20h ago
ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
→ No new info (linked only)
Tier D
BleepingComputer1d ago
Critical ServiceNow code execution flaw now exploited in attacks
→ No new info (linked only)
Tier D
SecurityWeek6d ago
Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow
→ No new info (linked only)
Tier B
CCCS Canada6d ago
ServiceNow security advisory (AV26-693)
→ No new info (linked only)
Tier B
BSI Advisories7d ago
[NEU] [hoch] ServiceNow AI Platform: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier C
VulDB7d ago
CVE-2026-6875 | ServiceNow prior Brazil EA/Brazil GA AI Platform Remote Code Execution
→ No new info (linked only)
CVSS 3.19.5 CRITICAL
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
Australia Patch 2Yokohama Patch 12 Hot Fix 1bYokohama Patch 13Zurich Patch 7bZurich Patch 9Brazil EABrazil GA
CWECWE-94
PublishedJul 13, 2026
Last enriched2h agov7
Tags
pre-authrcecode-injectionin-the-wild
Trending Score134🔥
Source articles8
Independent7
Info Completeness12/14
Missing: epss, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 13, 2026
Added to CISA KEV
Jul 13, 2026
Discovered by ZDM
Jul 13, 2026
Updated: description, severity
Jul 13, 2026
Actively Exploited
Jul 14, 2026
Exploit Available
Jul 14, 2026
Patch Available
Jul 14, 2026
Updated: description, severity, exploitAvailable, activelyExploited
Jul 14, 2026
Updated: affectedVersions, severity, cweIds
Jul 14, 2026
Updated: cvssEstimate
Jul 15, 2026
Updated: tags
Jul 20, 2026
Updated: mitreAttack
Jul 21, 2026

Version History

v7
Last enriched 2h ago
v7Tier D2h ago

Added MITRE ATT&CK technique T1190 (Exploit Public-Facing Application) based on confirmed remote exploitation details.

mitreAttack
via SecurityWeek
v6Tier D20h ago

Added MITRE ATT&CK technique T1190 (Exploit Public-Facing Application) and new tags identifying this as a pre-auth RCE with code injection being actively exploited in the wild.

tags
via Help Net Security
v5Tier D5d ago

Updated CVSS score to 9.5 and clarified that patches were deployed to hosted instances.

cvssEstimate
via SecurityWeek
v4Tier B6d ago

Updated severity to CRITICAL, added new affected versions, and included CWE-94.

affectedVersionsseveritycweIds
via CCCS Canada
v3Tier B7d ago

Updated description with new technical details and changed severity to HIGH, indicating that exploitation is possible.

descriptionseverityexploitAvailableactivelyExploited
via BSI Advisories
v2Tier C7d ago

Updated severity to CRITICAL, corrected exploit availability to false, and provided a new description with additional details.

descriptionseverity
via VulDB
v17d ago

Initial creation