ServiceNow CVE-2026-6875
Sandbox Escape in ServiceNow AI Platform
Risk & exploitation
No EPSS score is published for this CVE yet; priority uses the available signals. Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
ServiceNow has addressed a critical remote code execution vulnerability in the ServiceNow AI Platform, tracked as CVE-2026-6875 and disclosed on 2026-07-13 (advisory KB3137947). Under certain circumstances the flaw allows an unauthenticated user to escape the server-side script sandbox and execute code within the ServiceNow platform.
ServiceNow deployed a security update to hosted instances and issued equivalent updates to self-hosted customers and partners. The fix ships as Guarded Script (Server-Side Sandbox Runtime Replacement, KB2944435): guest (unauthenticated) traffic is fully enforced immediately on every upgraded instance, while enforcement for authenticated traffic phases in automatically over roughly four weeks on hosted instances — on-premises instances begin detection automatically but advance each enforcement phase manually. ServiceNow states it is not currently aware of exploitation against ServiceNow instances.
Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Brazil | Brazil EA / Brazil GA |
| Australia | Patch 2 |
| Zurich | Patch 7b / Patch 9 |
| Yokohama | Patch 12 Hot Fix 1b / Patch 13 |
Source & attribution
Per-release fixed-in verified 2026-07-15 against ServiceNow advisory KB3137947 (support.servicenow.com, public) — 'CVE-2026-6875 Sandbox Escape in ServiceNow AI Platform', published 2026-07-13. Brazil (EA / GA) was absent from the CVE.org CNA draft and added from the KB matrix; Australia Patch 2, Zurich Patch 7b / Patch 9, and Yokohama Patch 12 Hot Fix 1b / Patch 13 all confirmed against the KB. The fix ships as Guarded Script / Server-Side Sandbox Runtime Replacement (KB2944435).
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(e)
- NIS2 Art.23§1
- DORA Art.9§1
- DORA Art.17§1
- ISO 27001:2022 A.8.8
- GDPR Art.32
Decision support, not a reporting determination.
References
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.