ServiceNow has released security updates to address a critical remote code execution vulnerability in its AI Platform.
This vulnerability, tracked as CVE-2026-6875, could allow unauthenticated attackers to execute code within affected ServiceNow environments. The issue is described as a sandbox-escape flaw affecting the ServiceNow AI Platform.
Critical ServiceNow AI Platform Flaw
According to ServiceNow advisory KB3137947, an attacker could exploit this vulnerability under certain conditions without needing to authenticate to a target instance. However, the company currently reports no known active exploitation targeting ServiceNow instances.
Sandboxing aims to isolate untrusted or restricted workloads from the broader application environment. A successful sandbox escape can breach this isolation, permitting an attacker to access resources or perform operations outside the sandbox’s permissions.
In the case of the ServiceNow AI Platform, CVE-2026-6875 could enable an unauthenticated attacker to execute code within the platform. ServiceNow has not publicly disclosed technical details about the exploit, attack prerequisites, affected components, or a proof of concept.
Unauthenticated remote code execution vulnerabilities pose a high operational risk. Attackers can potentially exploit these vulnerabilities without needing valid accounts, phishing access, or pre-existing tenant privileges.
Consequences of unauthorized code execution in an enterprise workflow and IT service management environment can include unauthorized access to sensitive business data, manipulation of workflows, theft of credentials or API tokens, lateral movement through connected enterprise applications, and disruption of critical IT operations.
Affected Releases and Fixes
ServiceNow has addressed this vulnerability by deploying a security update to hosted instances. Relevant fixes are also available for self-hosted customers and partners.
The vulnerability has been fixed in the following ServiceNow family releases and patches:
- Brazil EA and Brazil GA
- Australia Patch 222
- Zurich Patch 7b7b7b
- Zurich Patch 999
- Yokohama Patch 121212 Hot Fix 1b1b1b
- Yokohama Patch 131313
Organizations using affected self-hosted deployments should identify their current ServiceNow family and patch level, then upgrade to an applicable fixed version as soon as possible.
Customers utilizing ServiceNow-hosted instances should verify that their environment has received the vendor-deployed update, especially where update schedules, change-control requirements, or specialized configurations could affect remediation validation.
ServiceNow advises customers to promptly apply the appropriate updates or upgrade to a patched release. Security teams should also review administrative activity, integration credentials, API usage, and any unusual workflow changes for signs of unauthorized behavior.
Organizations should prioritize addressing CVE-2026-6875 in their vulnerability management processes due to its potential for unauthenticated attacks and its impact on a platform frequently connected to identity systems, cloud services, endpoint management tools, and internal business applications.
The advisory was last updated on July 13, 2026. Additional maintenance information can be found in ServiceNow’s April 2026 security maintenance knowledge base articles, KB2930717 and KB2930740.
Interact with Cyber Threats in Windows, Linux, macOS VMs to Trigger Full Attack Chain - Analyse Malware & Phishing with ANY RUN





