ServiceNow’s sandbox escape RCE hole now exploited in the wild

Source: CSO Online

Author: unknown

URL: https://www.csoonline.com/article/4198993/servicenows-sandbox-escape-rce-hole-now-exploited-in-the-wild.html

ONE SENTENCE SUMMARY:

ServiceNow patched CVE-2026-6875 sandbox-escape RCE, but in-wild variants emerged, challenging defenses and expanding AI-driven SaaS risk.

MAIN POINTS:

  1. Defused reported active exploitation of ServiceNow pre-auth sandbox-escape RCE CVE-2026-6875.
  2. Attackers altered techniques beyond Searchlight Cyber’s PoC to bypass new mitigations.
  3. ServiceNow implemented five code mitigations that neutralized the original exploit methodology.
  4. Observed exploitation appears limited so far to one incident by one actor.
  5. ServiceNow says it has not seen evidence affecting instances it hosts.
  6. Sandbox bypass undermines longstanding reliance on scripting containment for untrusted code.
  7. Variant techniques reduce effectiveness of signature-based detections built on initial PoC.
  8. Cloud-tenant compromise can pivot into corporate networks via integrations like MID Server.
  9. ServiceNow data concentration (HR, CMDB, ticketing) amplifies attacker visibility and impact.
  10. AI features enlarge blast radius through agents, tokens, service accounts, and delegated permissions.

TAKEAWAYS:

  1. Prioritize rapid patching for core SaaS platforms as part of internal attack surface.
  2. Validate sandbox boundary architecture and testing for every AI-enabled SaaS vendor.
  3. Assume exploit variants will evolve quickly; rely on behavior-based detections and hardening.
  4. Reassess threat models after AI feature rollouts, especially for pre-auth exposure.
  5. Treat sandboxes as risk-reduction controls, not guarantees, amid continuous exploit availability.