Hackers are Actively Exploiting ServiceNow Vulnerability in the Wild

In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog Writer

Spread the love

A critical ServiceNow vulnerability, tracked as CVE-2026-6875, is being actively exploited to allow unauthenticated attackers to escape the script sandbox and execute code on affected systems.

The vulnerability specifically impacts the ServiceNow AI Platform and is described as a pre-authentication sandbox escape. This means that an attacker may not need to have a valid ServiceNow account to attempt to compromise a vulnerable instance.

ServiceNow has indicated that under certain conditions, this issue could enable unauthenticated users to execute code within the platform.

Security researchers at Searchlight Cyber’s Assetnote discovered CVE-2026-6875 and reported it to ServiceNow on April 1, 2026, finding that attacker-controlled input could reach a server-side GlideRecord query path and trigger JavaScript evaluation.

The vulnerable path reportedly includes the /assessment_thanks.do endpoint. Attackers can use this route to access a pre-authentication script execution point and exploit weaknesses in the script sandbox to achieve code execution.

Active Exploitation of ServiceNow Flaw

The seriousness of this flaw is underscored by the potential for successful exploitation, which could grant attackers the ability to execute code within the ServiceNow platform.

Researchers at Searchlight Cyber have warned that this access could allow attackers to read sensitive platform data, create administrative accounts, and potentially execute commands through configured MID Servers or proxy infrastructure.

ServiceNow has already issued security updates for this vulnerability. The company deployed updates to hosted instances and made relevant patches available for self-hosted customers and partners.

Organizations using self-managed ServiceNow deployments should immediately apply the latest security update or upgrade to a patched release, and enable Guarded Script to help mitigate sandbox escape attacks.

These protections limit the types of JavaScript expressions that can be executed in sandboxed contexts, restricting constructs such as variable declarations, control flow, function declarations, assignments, and multiple statements.

Threat intelligence firm Defused said the vulnerability is being exploited in the wild, making immediate mitigation more urgent for defenders.

Initially, ServiceNow’s advisory stated that it was unaware of any exploitation however, subsequent reports based on telemetry from Defused indicated that exploit attempts began shortly after the vulnerability was publicly disclosed.

Security teams should review the status of ServiceNow updates, inspect logs for suspicious requests targeting /assessment_thanks.do, and investigate unusual parameters associated with sysparm_assessable_type.

Organizations should also monitor for unexpected administrative account creations, abnormal script activity, and suspicious actions involving MID Servers.

CVE-2026-6875 highlights the security risks posed when unauthenticated input reaches powerful server-side scripting and query functions.

As exploitation activity is now being observed, patching exposed and self-hosted ServiceNow instances should be treated as a high-priority task for incident prevention.

The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment