Source: CSO Online
Author: unknown
URL: https://www.csoonline.com/article/4198993/servicenows-sandbox-escape-rce-hole-now-exploited-in-the-wild.html
ONE SENTENCE SUMMARY:
ServiceNow patched CVE-2026-6875 sandbox-escape RCE, but in-wild variants emerged, challenging defenses and expanding AI-driven SaaS risk.
MAIN POINTS:
- Defused reported active exploitation of ServiceNow pre-auth sandbox-escape RCE CVE-2026-6875.
- Attackers altered techniques beyond Searchlight Cyber’s PoC to bypass new mitigations.
- ServiceNow implemented five code mitigations that neutralized the original exploit methodology.
- Observed exploitation appears limited so far to one incident by one actor.
- ServiceNow says it has not seen evidence affecting instances it hosts.
- Sandbox bypass undermines longstanding reliance on scripting containment for untrusted code.
- Variant techniques reduce effectiveness of signature-based detections built on initial PoC.
- Cloud-tenant compromise can pivot into corporate networks via integrations like MID Server.
- ServiceNow data concentration (HR, CMDB, ticketing) amplifies attacker visibility and impact.
- AI features enlarge blast radius through agents, tokens, service accounts, and delegated permissions.
TAKEAWAYS:
- Prioritize rapid patching for core SaaS platforms as part of internal attack surface.
- Validate sandbox boundary architecture and testing for every AI-enabled SaaS vendor.
- Assume exploit variants will evolve quickly; rely on behavior-based detections and hardening.
- Reassess threat models after AI feature rollouts, especially for pre-auth exposure.
- Treat sandboxes as risk-reduction controls, not guarantees, amid continuous exploit availability.