Vulnerabilities

ServiceNow Patches Critical RCE Flaw Already Exploited in the Wild

ServiceNow Patches Critical RCE Flaw Already Exploited in the Wild

ServiceNow patched a critical remote code execution vulnerability on July 13, 2026. Attackers were exploiting it within days. The flaw, CVE-2026-6875, carries a CVSS score of 9.8 and requires no authentication. Anyone who can reach the affected endpoint can execute arbitrary code on the underlying server.

Defused security researchers confirmed active exploitation in a statement to BleepingComputer, “We are observing in-the-wild exploitation.” No further technical detail about the specific attack campaigns has been published by a Tier 1 source at the time of writing.

Five CVEs, One Platform, One Patch Window

CVE-2026-6875 is the most severe of five CVEs addressed in ServiceNow’s July 13 release. The others are CVE-2026-0542, CVE-2024-4879, CVE-2024-5178 and CVE-2024-5217. All five affect the ServiceNow Now Platform and its AI Platform variant. SentinelOne’s vulnerability database lists CVE-2026-0542 as a separate RCE path in the same AI Platform component which means organisations that patch selectively rather than upgrading to the current release may close one entry point and leave others open.

Deepwatch documented a prior exploitation pattern against ServiceNow that involved chaining multiple vulnerabilities to dump internal user lists before escalating access. That playbook is directly relevant here with 3 unauthenticated RCE vectors present in the same platform, defenders should not assume a single patch resolves the exposure.

The source data includes the claim that 85% of Fortune 500 companies use ServiceNow. That figure originates from ServiceNow’s own marketing materials. Treat it as a sales statistic, not an independent measurement of exposure.

Enterprise IT Management Platforms Are a Specific Category of Target

ServiceNow sits at the centre of IT operations for large organisations including asset management, access provisioning, incident response workflows, HR service delivery. An attacker with code execution on a ServiceNow instance does not just own a single application. They have access to the data flows between departments potentially including credential stores, ticketing data documenting internal vulnerabilities and integration tokens for connected systems.

This is not a web application sitting on the edge of the network. It is the system administrators use to manage everything else. That makes unauthenticated RCE in this context materially worse than the same flaw in a less connected product.

Fortinet’s FortiGuard outbreak alert for the ServiceNow RCE campaign, linked in the references below, provides additional indicators of compromise for organisations that want to check for prior access before patching.

Patch Now, Then Check Whether You Were Already Compromised

Upgrade to the version ServiceNow specifies in its July 13 advisory. Applying individual patches to an older release is not sufficient when multiple CVEs affect the same component. The full upgrade is the only way to close all 5 documented vectors simultaneously.

If your ServiceNow instance is internet-facing, treat it as potentially compromised before you patch. Review access logs from the days immediately following July 13 for anomalous activity on platform endpoints. Check for new integration accounts, unexpected API tokens or changes to workflow automation rules that your team did not authorise. Fortinet’s IOC list is a practical starting point for that review.

If an immediate upgrade is not possible, restrict external access to the platform at the network perimeter as a temporary control. That reduces exposure but does not eliminate it for internal threat actors or for systems already accessed before the restriction was applied.

CISA’s Known Exploited Vulnerabilities catalogue had not listed CVE-2026-6875 at the time of writing. Given confirmed in-the-wild exploitation, that listing should be expected shortly. Organisations under CISA’s BOD 22-01 binding operational directive or those using the KEV catalogue as a patching priority signal should not wait for the listing before acting.

References

  1. Critical ServiceNow code execution flaw now exploited in attacks
  2. SentinelOne Vulnerability Database: CVE-2026-0542
  3. Fortinet FortiGuard Outbreak Alert: ServiceNow RCE
  4. Attackers exploit chain of vulnerabilities in ServiceNow
  5. Critical ServiceNow AI Platform Flaw Allows Remote Code Execution Attacks
  6. CISA Known Exploited Vulnerabilities Catalogue

This post is also available in: Svenska

Per Häggdahl

Per Häggdahl is Head of Business Unit and CISO at eBuilder Security, with more than 20 years securing systems for banks, central banks, stock exchanges and central securities depositories, now leading the team that brings that same enterprise-grade protection to organisations of every size.