Particle.news

Attackers Exploit Critical ServiceNow RCE Flaw

Unauthenticated sandbox escape lets attackers run remote code on ServiceNow, creating immediate risk for unpatched self-hosted instances.

Overview

  • Security firm Searchlight Cyber disclosed the bug (CVE-2026-6875) on July 13 and said it allows unauthenticated code injection that can break the platform’s script sandbox and enable full instance compromise.
  • ServiceNow applied fixes to its hosted cloud instances and issued patches and a Guarded Script sandbox restriction for self-hosted customers on July 13, and it is urging customers to upgrade.
  • Defused and other researchers confirmed active exploitation that began on Friday, with attacker payloads targeting the same /assessment_thanks.do endpoint but using a different sandbox-escape gadget than the published proof-of-concept.
  • ServiceNow’s advisory still says it is not aware of verified customer impact even as third-party teams report weaponization, so administrators of self-hosted instances should treat the public reports as an urgent call to patch and monitor logs.
  • Because ServiceNow runs core workflows at many large companies, the flaw can expose sensitive data and internal proxies to remote takeover, so expect ongoing scans, incident investigations, and potential follow-on attacks if unpatched systems remain reachable.