CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-6875

criticalpublic exploitcovered by 3 sourcesfirst seen 2026-07-13
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-6875 is indexed in GitHub PoC and Nuclei. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
Serial number: AV26-693 Date: July 14, 2026 Updated: July 20, 2026 On July 13, 2026, ServiceNow published a security advisory to address a critical vulnerability in the following products: Brazil - versions prior to Brazil EA and Brazil GA Australia - versions prior to Australia Patch 2 Zurich - versions prior to Zurich Patch 7b and Zurich Patch 9 Yokohama - versions prior to Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13 Update 1 Open-source reporting indicates that CVE-2026-6875 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. [Security Advisory] CVE-2026-6875 - Sandbox Escape in ServiceNow AI Platform ServiceNow security advisories

CSIRTS triage

vendor: ServiceNowproduct: Brazil, Australia, Zurich, YokohamaOtheraffected: prior to Brazil EA, Australia Patch 2, Zurich Patch 7b and 9, Yokohama Patch 12 Hot Fix 1b and 13
What
A critical sandbox escape vulnerability exists in the ServiceNow AI Platform.
Who is affected
Users of affected ServiceNow products prior to the specified patches.
Urgency
Remediation is urgent due to the critical nature of the vulnerability.
Action
Update to the latest patches for the affected products.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-6875

Get an email if CVE-2026-6875 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Exploit availability

Public exploit or proof-of-concept code for CVE-2026-6875 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.

Advisory coverage (3)

External references

NVD record for CVE-2026-6875

CVE.org record

Embed the live status

CVE-2026-6875 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-6875 status](https://www.csirts.com/badge/CVE-2026-6875)](https://www.csirts.com/cve/CVE-2026-6875)