CVE-2026-6875
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-6875 is indexed in GitHub PoC and Nuclei. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
Serial number: AV26-693 Date: July 14, 2026 Updated: July 20, 2026 On July 13, 2026, ServiceNow published a security advisory to address a critical vulnerability in the following products: Brazil - versions prior to Brazil EA and Brazil GA Australia - versions prior to Australia Patch 2 Zurich - versions prior to Zurich Patch 7b and Zurich Patch 9 Yokohama - versions prior to Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13 Update 1 Open-source reporting indicates that CVE-2026-6875 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. [Security Advisory] CVE-2026-6875 - Sandbox Escape in ServiceNow AI Platform ServiceNow security advisories
CSIRTS triage
- What
- A critical sandbox escape vulnerability exists in the ServiceNow AI Platform.
- Who is affected
- Users of affected ServiceNow products prior to the specified patches.
- Urgency
- Remediation is urgent due to the critical nature of the vulnerability.
- Action
- Update to the latest patches for the affected products.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-6875
Get an email if CVE-2026-6875 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Elevated exploitation risk24.5% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 98% of all EPSS-scored CVEs.
Exploit availability
Public exploit or proof-of-concept code for CVE-2026-6875 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.
- GitHub PoCPublic proof-of-concept repositories on GitHub reference this CVE.look it up ↗
- NucleiA nuclei-templates detection/PoC template exists for this CVE.look it up ↗
Advisory coverage (3)
- high[NEW] [high] ServiceNow AI Platform: Vulnerability allows code executioncert-bund · 2026-07-21
- criticalServiceNow security advisory (AV26-693) – Update 1cccs · 2026-07-20
- unknownCVE-2026-6875: ServiceNow has addressed a remote code execution vulnerability that was identified in the Servi…nvd · 2026-07-13
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-6875)