Overview
- Security firm Searchlight Cyber disclosed the bug (CVE-2026-6875) on July 13 and said it allows unauthenticated code injection that can break the platform’s script sandbox and enable full instance compromise.
- ServiceNow applied fixes to its hosted cloud instances and issued patches and a Guarded Script sandbox restriction for self-hosted customers on July 13, and it is urging customers to upgrade.
- Defused and other researchers confirmed active exploitation that began on Friday, with attacker payloads targeting the same /assessment_thanks.do endpoint but using a different sandbox-escape gadget than the published proof-of-concept.
- ServiceNow’s advisory still says it is not aware of verified customer impact even as third-party teams report weaponization, so administrators of self-hosted instances should treat the public reports as an urgent call to patch and monitor logs.
- Because ServiceNow runs core workflows at many large companies, the flaw can expose sensitive data and internal proxies to remote takeover, so expect ongoing scans, incident investigations, and potential follow-on attacks if unpatched systems remain reachable.