ServiceNow’s sandbox escape RCE hole now exploited in the wild
Summary
ServiceNow patched a sandbox escape RCE vulnerability (CVE-2026-6875, a flaw that lets attackers run unauthorized code on systems they don't control) last week, but attackers are already exploiting it in the wild using modified techniques. Security experts warn this is especially dangerous because the vulnerability affects ServiceNow's sandbox (the security container designed to safely run untrusted code), and a compromise could give attackers access to sensitive data like HR records and potentially spread to corporate networks through integrations.
Solution / Mitigation
ServiceNow has issued updates and patches to address the vulnerability. The company stated: "We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so."
Classification
Affected Vendors
Related Issues
Original source: https://www.csoonline.com/article/4198993/servicenows-sandbox-escape-rce-hole-now-exploited-in-the-wild.html
First tracked: July 20, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 85%