HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Pre‑Auth RCE in ServiceNow AI Platform (CVE‑2026‑6875) Actively Exploited

ServiceNow’s AI Platform contains a pre‑authentication sandbox‑escape RCE (CVE‑2026‑6875) that attackers are exploiting in the wild. The flaw bypasses logical access controls, making timely patching and evidence collection essential for SOC 2 audit readiness.

LiveThreat™ Intelligence · 📅 July 20, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

Critical Pre‑Auth RCE in ServiceNow AI Platform (CVE‑2026‑6875) Actively Exploited

What It Is – A remote‑code‑execution vulnerability (CVE‑2026‑6875) in the ServiceNow AI Platform allows an unauthenticated attacker to escape the sandbox and run arbitrary code on the ServiceNow instance.

Exploitability – The flaw is being leveraged in the wild; Defused observed exploitation within days of the vendor‑issued patch. No public proof‑of‑concept is required – the attack works against the pre‑auth “/assessment_thanks.do” endpoint.

Affected Products – ServiceNow AI Platform (formerly Now Platform) – both hosted SaaS instances and self‑hosted deployments that have not applied the July 13 2026 security update.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Controls – Unauthenticated code execution bypasses logical access boundaries, directly violating the CC6.1 “Logical Access Control” criterion.
  • Patch Management Evidence – Continuous proof that critical patches are applied within the vendor‑defined SLA is required to demonstrate due diligence under the CC7.2 “System Operations” criterion.
  • Audit Trail Integrity – Exploited RCE can tamper with logs and audit records; maintaining immutable, verifiable logs is essential for a defensible SOC 2 audit.

Recommended Actions

  • Deploy ServiceNow’s July 13 2026 patch to all instances immediately; verify version numbers.
  • Conduct a focused control test mapping CVE‑2026‑6875 to SOC 2 CC6.1 (Logical Access Control) and CC7.2 (System Operations).
  • Capture patch‑deployment evidence (change‑request tickets, SHA‑256 hashes) for audit review.
  • Enable and monitor detailed request‑logging for the /assessment_thanks.do endpoint; alert on anomalous pre‑auth activity.
  • Review and harden sandbox configurations; enforce least‑privilege execution contexts.

Source: BleepingComputer – Critical ServiceNow code execution flaw now exploited in attacks

📰 Original Source
https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →