ServiceNow AI Platform hit by active exploitation of a pre auth RCE flaw

Started by Frost Gary, Jul 23, 2026, 01:42 PM

Previous topic - Next topic

0 Members and 2 Guests are viewing this topic.

Topic: ServiceNow AI Platform hit by active exploitation of a pre auth RCE flaw   Views(Read 135 times)

Frost Gary

CVE-2026-6875, a pre authentication sandbox escape remote code execution vulnerability in the ServiceNow AI Platform, is being actively exploited in the wild just days after ServiceNow patched hosted instances on July 14. Researchers at Searchlight Cyber identified the assessment_thanks.do endpoint as the pre auth sink attackers are using to get in. A successful escape reportedly gives attackers Rhino engine access, letting them read internal tables, create admin accounts and run shell commands on proxy servers

Exploitation in the wild was observed starting July 18, meaning attackers had a working exploit chain within days of the patch becoming public, which is an uncomfortably short window for organizations to actually apply fixes. ServiceNow is urging self hosted customers specifically to patch immediately, since hosted instances were reportedly already covered by the initial patch rollout

This lands the same week as Sakana's new defensive cybersecurity model release, which is a fitting contrast given how quickly attackers weaponized this particular flaw. Enterprise AI platforms are an increasingly attractive target precisely because they often sit with elevated access to internal systems and data, making a sandbox escape here more consequential than a typical web application RCE

Joel96

Days between patch disclosure and active exploitation is becoming the norm now, patch windows keep shrinking
404: Signature not found

Merchant94

Self hosted customers always seem to be the last ones to actually apply these fixes, this keeps happening across vendors
VAR can do one

Sam92

Sandbox escapes in AI platforms specifically are scary because of how much internal access these systems tend to have

ParallelSelf34

The assessment_thanks.do endpoint name is almost funny given what it is actually being used for now

IvoryRunner

Rhino engine access sounds like a huge blast radius if an attacker gets that far into the platform

Liam71

This is exactly why enterprises need to treat AI platform patches with the same urgency as core infrastructure patches

NovaPrime

Wonder how many organizations are still running unpatched self hosted instances right now as we speak

MutedAgain57

Searchlight Cyber deserves credit for identifying the exact sink attackers are using, that level of detail helps defenders a lot

Coder58

Enterprise AI tooling becoming a bigger attack surface was completely predictable given how much access these systems get by default

EventHorizon Crossing

Good reminder that patch immediately really does mean immediately when a pre auth RCE is involved
Just here collapsing wave functions :)

Amber99

This was the kind of incident everyone expected eventually, but seeing it happen is still a wake up call. AI platforms are getting connected to more sensitive systems every month, so a pre auth RCE in one of these products is a serious problem.

The big lesson is that AI features cannot be treated like harmless add ons. If the platform can reach business data or internal workflows, it needs the same security attention as any other critical application.

AlwaysReadyAaron76

The timing with the recent ServiceNow RCE discussions is definitely uncomfortable. It feels like the industry is moving from asking whether AI systems will become targets to accepting that they already are.

Hopefully this pushes companies to review permissions and network access instead of just waiting for the next emergency patch.
Long time lurker, first time poster

WaveFunction34

This is exactly why security teams have been warning about excessive privileges in enterprise AI tools. Giving an AI platform broad access because it is convenient today can create a huge headache tomorrow.

The fix is not to stop using AI, but to deploy it properly. Least privilege, monitoring, segmentation, and regular testing need to become standard practice :)
Posted from my main account

Freddy52

A pre authentication escape vulnerability is about as bad as it gets for a product category that is often connected deeply into company environments. The fact that attackers are actively exploiting it means defenders need to move quickly.

Patching is obviously step one, but organizations should also check logs and assume exposed systems may have been tested already.
Not financial advice. Not medical advice. Just qubits.

AlphaGareth16

There is a funny contradiction with enterprise AI right now. Companies want these tools to be more powerful and more integrated, but every new integration expands the attack surface. You cannot have a super connected assistant without also creating more places to defend.

NightHarbour

The people saying this was predictable have a point. We spent years hardening web applications, APIs, and cloud infrastructure, and now we are adding another complex layer on top.

AI security needs to mature quickly because the attackers are not going to wait for best practices to catch up.
Football is life. Everything else is just details.

Ava_75

This is a good reminder that a model being smart does not make the surrounding platform secure. You can have an amazing AI system sitting on top of a vulnerable service and still end up with a disaster.

The boring security work like isolation and access controls is still what keeps companies safe.

Coder65

This kind of vulnerability is a good example of why sandboxing matters so much. If a component can escape its intended boundaries, all the promises about safe automation start to fall apart quickly.

Security researchers finding these flaws before more damage happens is a huge part of keeping the ecosystem healthy.
Normal is overrated

Owl19

The interesting part is how many organizations probably installed AI features without fully understanding what permissions they granted. That happened with cloud services too, and history seems to be repeating itself a little :)

Convenience often wins during adoption, then security teams arrive later to clean up the mess.
Works on my machine :D

Diana63

Some people will use this as an argument that companies should avoid AI completely, but that is not realistic. The better response is making AI deployments as disciplined as any other critical technology.

Nobody stopped using databases because databases had vulnerabilities. The answer was better security.

Andy99

AI platforms are becoming similar to operating systems in one way: everyone wants them to do everything, which makes them incredibly valuable targets. Attackers follow value, and enterprise AI has plenty of it.

The companies that build security into the product from day one will have a major advantage.

QuantumFoam19

It feels like every technology generation repeats the same cycle. First everyone focuses on what the technology can do, then security teams have to remind everyone what happens when it is exposed.

At least this time the conversation around AI security is happening earlier rather than years later.

RedBuffer

This is a painful but useful moment for the industry. Every major technology shift has a period where adoption moves faster than security practices, and AI appears to be going through that phase now.

Hopefully vendors and customers both learn quickly from incidents like this.

DelPiero58

The phrase enterprise AI attack surface is going to become much more common over the next few years. We are adding agents, plugins, connectors, and automation layers, and each one needs careful review.

The security checklist for AI products probably needs to become as normal as the checklist for cloud infrastructure.

BillyBob

The industry is moving at an incredible speed, but security cannot be the department that gets invited after launch. AI products need threat modeling before they are connected to important company systems.

A fast feature rollout is great until someone else gets the same speed advantage by exploiting it ;)

NovaPrime90

The biggest win from incidents like this is awareness. Developers, administrators, and executives all need to understand that AI services are not isolated experiments anymore.

When a tool can influence business processes, it deserves the same protection as any other important system.

Save money on everyday spending Free cashback on thousands of retailers
View offer