Skip to content
Rush Commerce
Software & Dev2 min read

ServiceNow RCE is being exploited — patch your platform

CVE-2026-6875, an unauthenticated RCE in the ServiceNow AI Platform, is under active attack days after the self-hosted patch shipped. Patch window: hours.

If ServiceNow runs your IT tickets, HR requests, or internal workflows, stop and check your version. CVE-2026-6875, a critical unauthenticated remote code execution flaw in the ServiceNow AI Platform, is now being exploited in the wild — and the attacks started within days of the fix landing for self-hosted customers. This is the boring, load-bearing software that touches everything, and the window between "patch available" and "patch or get owned" was measured in days, not weeks.

What actually happened

Per BleepingComputer, the bug lets an unauthenticated attacker escape the ServiceNow sandbox and execute code remotely — no login required. It was originally reported by Searchlight Cyber back on April 1. ServiceNow patched its hosted instances starting in April, but security updates for self-hosted deployments only shipped July 13. Days later, researchers at Defused observed active exploitation against exposed self-hosted instances. ServiceNow's guidance is blunt: upgrade to a patched release as soon as possible.

The uncomfortable detail is the timeline. Self-hosted customers had a matter of days between getting the fix and seeing real attacks — and anyone who hadn't inventoried their internet-facing ServiceNow instances didn't even know the clock was running. Security firm Rescana flagged it as active-exploitation, unauthenticated, and pre-auth — the trifecta that gets a CVE weaponized fast.

Why this matters for your business

You didn't write ServiceNow, but its risk is your risk. Platforms like this are wired into your identity system, your ticket data, often your production network — so a sandbox escape isn't a contained problem, it's a foothold. "It's a vendor's product" is not a defense when the box lives on your network and your name is on the breach.

Two habits turn this from an emergency into a Tuesday. First, know what you run: a current inventory of your internet-facing systems and which ones are self-hosted (you patch those, not the vendor). Second, have a patch SLA in hours for internet-facing, unauthenticated-RCE-class bugs — pre-approved, tested, and rehearsed, so a critical advisory triggers a runbook instead of a meeting. The attackers already automated their side. Your response has to be faster than their scan.

Key takeaways

  • CVE-2026-6875 is an unauthenticated pre-auth RCE in the ServiceNow AI Platform — sandbox escape to code execution
  • Self-hosted patches shipped July 13; active exploitation followed within days. Hosted instances were patched back in April
  • If you run self-hosted ServiceNow, patch now and check exposed instances for signs of compromise
  • The durable fix is process: a live inventory of internet-facing systems and a patch SLA measured in hours for critical RCEs

No inventory, no patch SLA, no idea what's exposed? We build the patch-and-monitor discipline that turns critical CVEs into routine deploys instead of fire drills. Let's talk.

Sources: BleepingComputer, Rescana.

  • #servicenow
  • #cve-2026-6875
  • #rce
  • #patching
  • #vendor-risk
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.