Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Empirical Security Raises $25 Million in Series A Funding

    July 21, 2026

    SpaceX Starlink Communications Will Be in Every Tesla Cybercab

    July 21, 2026

    Assassin’s Creed Shadows for the Switch 2 is almost half price, but you’ll need to be quick

    July 21, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
    Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
    Cybersecurity

    Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

    The Tech GuyBy The Tech GuyJuly 21, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    A critical remote code execution vulnerability that was recently patched in the ServiceNow AI platform is reportedly being exploited in the wild.

    Advertisement

    The security hole is tracked as CVE-2026-6875 and it has been described as a sandbox escape issue that an unauthenticated attacker can exploit in certain circumstances to execute arbitrary code.

    When it announced the availability of patches on July 14, ServiceNow said a security update addressing the vulnerability had been deployed to hosted instances. However, self-hosted customers have to install the patches themselves.

    On the same day, cybersecurity firm Searchlight Cyber disclosed technical details and showed how the vulnerability can be exploited. 

    Threat intelligence firm Defused reported on July 18 that it had seen in-the-wild exploitation of CVE-2026-6875, leveraging information Searchlight Cyber had released. 

    Defused initially said the exploit reached the same outcome as Searchlight’s proof-of-concept but through a slightly different method. On Monday, however, the firm issued a correction, saying that closer analysis showed the captured payload was in fact identical to Searchlight Cyber’s own.

    Advertisement. Scroll to continue reading.

    The vendor’s initial advisory stated it had no knowledge of active exploitation, and as of this writing, that advisory has not been updated to reflect otherwise.

    “ServiceNow is aware of a cybersecurity company’s recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as CVE-2026-6875,” a ServiceNow spokesperson told SecurityWeek. “Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts.” 

    “We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so. In addition, we will continue to work directly with customers who need assistance in applying the patches,” the spokesperson added.

    There do not appear to be any other reports describing the exploitation of CVE-2026-6875, and there is a chance that the activity is being carried out by members of the cybersecurity industry seeking vulnerable systems.

    ServiceNow informed customers last month of an exploited vulnerability, but the company later clarified that the exploitation had been attributed to security researchers rather than attackers.

    ServiceNow vulnerabilities are not often exploited by threat actors. CISA’s KEV catalog currently includes only two flaws, both patched in 2024.

    Related: SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

    Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild

    Related: Fresh SharePoint Vulnerability Exploited Soon After Disclosure

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Empirical Security Raises $25 Million in Series A Funding

    July 21, 2026

    OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

    July 21, 2026

    SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

    July 20, 2026

    Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software

    July 20, 2026

    Chrome 150 Update Patches Severe Memory Safety Bugs

    July 20, 2026

    Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack

    July 19, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026282 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026171 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Empirical Security Raises $25 Million in Series A Funding

    July 21, 2026

    SpaceX Starlink Communications Will Be in Every Tesla Cybercab

    July 21, 2026

    Assassin’s Creed Shadows for the Switch 2 is almost half price, but you’ll need to be quick

    July 21, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.