ServiceNow security advisory (AV26-693) – Update 1
Serial number: AV26-693 Date: July 14, 2026 Updated: July 20, 2026 On July 13, 2026, ServiceNow published a security advisory to address a critical vulnerability in the following products: Brazil - versions prior to Brazil EA and Brazil GA Australia - versions prior to Australia Patch 2 Zurich - versions prior to Zurich Patch 7b and Zurich Patch 9 Yokohama - versions prior to Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13 Update 1 Open-source reporting indicates that CVE-2026-6875 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. [Security Advisory] CVE-2026-6875 - Sandbox Escape in ServiceNow AI Platform ServiceNow security advisories
CSIRTS triage
- What
- A critical sandbox escape vulnerability exists in the ServiceNow AI Platform.
- Who is affected
- Users of affected ServiceNow products prior to the specified patches.
- Urgency
- Remediation is urgent due to the critical nature of the vulnerability.
- Action
- Update to the latest patches for the affected products.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Brazil, Australia, Zurich, Yokohama
Get an email when a new Brazil, Australia, Zurich, Yokohama advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/servicenow-security-advisory-av26-693
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Elevated exploitation riskCVE-2026-687524.5% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 98% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-6875 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30