← All CVEs & advisories

ServiceNow CVE-2026-6875

Sandbox Escape in ServiceNow AI Platform

RCECVSS 4.0 9.5Priority 29Disclosed 2026-07-13Verified

Risk & exploitation

PriorityMedium · 29/100
EPSSnot published
CISA KEVNo
Public exploitNone indexed

No EPSS score is published for this CVE yet; priority uses the available signals. Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

ServiceNow has addressed a critical remote code execution vulnerability in the ServiceNow AI Platform, tracked as CVE-2026-6875 and disclosed on 2026-07-13 (advisory KB3137947). Under certain circumstances the flaw allows an unauthenticated user to escape the server-side script sandbox and execute code within the ServiceNow platform.

ServiceNow deployed a security update to hosted instances and issued equivalent updates to self-hosted customers and partners. The fix ships as Guarded Script (Server-Side Sandbox Runtime Replacement, KB2944435): guest (unauthenticated) traffic is fully enforced immediately on every upgraded instance, while enforcement for authenticated traffic phases in automatically over roughly four weeks on hosted instances — on-premises instances begin detection automatically but advance each enforcement phase manually. ServiceNow states it is not currently aware of exploitation against ServiceNow instances.

Affected releases & fixed-in

ReleaseFixed in
BrazilBrazil EA / Brazil GA
AustraliaPatch 2
ZurichPatch 7b / Patch 9
YokohamaPatch 12 Hot Fix 1b / Patch 13
Source & attribution

Per-release fixed-in verified 2026-07-15 against ServiceNow advisory KB3137947 (support.servicenow.com, public) — 'CVE-2026-6875 Sandbox Escape in ServiceNow AI Platform', published 2026-07-13. Brazil (EA / GA) was absent from the CVE.org CNA draft and added from the KB matrix; Australia Patch 2, Zurich Patch 7b / Patch 9, and Yokohama Patch 12 Hot Fix 1b / Patch 13 all confirmed against the KB. The fix ships as Guarded Script / Server-Side Sandbox Runtime Replacement (KB2944435).

Regulatory mapping

Decision support, not a reporting determination.

Check your instance for CVE-2026-6875

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.