Skip to main content
Home/Blog/No Password Required. Hackers Are Already Inside ServiceNow. Is Your Organization Next?
Cybersecurity

No Password Required. Hackers Are Already Inside ServiceNow. Is Your Organization Next?

CVE-2026-6875 is a critical ServiceNow flaw that lets attackers in without a login. Active exploitation confirmed July 19. Here's what business leaders need to do right now.

July 21, 2026·7 min read

Here's a sentence that should get your attention: attackers can walk into your ServiceNow environment without a username or password. No phishing. No stolen credentials. No inside access. Just an internet connection and knowledge of a flaw that was publicly disclosed on July 13.

As of July 19, 2026, that flaw is being actively exploited.

If your organization runs ServiceNow — and if you're a mid-to-large enterprise, there's a strong chance you do — this is not a theoretical risk. It's a current one.

What Is CVE-2026-6875?

CVE-2026-6875 is a critical vulnerability in the ServiceNow AI Platform, scored 9.5 out of 10 on the CVSS severity scale. That's as bad as it gets without being a perfect score.

The flaw is what security researchers call a "sandbox escape" — a way for an attacker to break out of the restricted environment where code is supposed to run and execute their own commands on the underlying system. The alarming part: it requires no authentication whatsoever. No username. No password. No MFA to bypass. Just a crafted request to a publicly accessible endpoint, and an attacker potentially has full remote code execution capability on your ServiceNow instance.

The vulnerability was discovered by researcher Adam Kues of Searchlight Cyber, who reported it to ServiceNow in early April. ServiceNow pushed a patch to cloud-hosted instances almost immediately. They made patches available to self-hosted customers throughout June. The advisory was published July 13.

Within six days of public disclosure, attackers were actively exploiting it.

Why ServiceNow Is a High-Value Target

This matters beyond just a software patch because of what ServiceNow is. It's not a peripheral tool. For most organizations that use it, ServiceNow is the operational backbone — the platform where IT tickets are processed, HR workflows run, change management happens, and increasingly, where AI-driven automation is deployed.

That means a compromised ServiceNow instance isn't just a data problem. It's an operational problem. Attackers inside ServiceNow can potentially:

- Access support tickets containing sensitive employee or client information - Pivot into connected systems using the platform's extensive integrations - Exfiltrate internal documentation, credentials, and configuration data - Intercept or manipulate workflows in ways that affect business operations

The threat intelligence firm Defused, which confirmed active exploitation, noted that attackers are already adapting their methods — using a different path than the publicly documented proof-of-concept to evade detection. That kind of adaptation, in the first week of exploitation, signals organized threat actors, not script kiddies.

The Self-Hosted Problem

Here's where organizations fall into a common trap. ServiceNow's cloud-hosted customers received patches automatically — in some cases months ago. But organizations running self-hosted or partner-hosted instances? They received patches and updates throughout June, with the advisory published July 13. Applying those patches requires administrator action.

In most enterprises, that process goes through IT change management queues. Which means it takes time. Which means there's a window.

That window, right now, is being actively targeted.

ServiceNow has confirmed they're not aware of exploitation against their own hosted environments — but self-hosted instances are the exposure point. If you're not certain whether your organization runs self-hosted ServiceNow, that question needs an answer today, not next week.

The Pattern You Should Recognize

This isn't the first time we've seen this play out. In July alone, we've watched attackers exploit Microsoft SharePoint vulnerabilities within days of disclosure. We watched the BlueHammer Defender zero-day get weaponized in ransomware deployments. We watched FortiGate firewall credentials get harvested at scale.

The pattern is consistent: a critical vulnerability is disclosed, patches are released, and attackers move faster than enterprise patching cycles. Patch lag — the time between when a fix is available and when it's actually applied — is one of the most reliable attack vectors in modern cybercrime.

Verizon's 2026 Data Breach Investigations Report found a median enterprise vulnerability remediation time of 44 days. Attackers needed six days after CVE-2026-6875 was public before they were already in.

The math doesn't work in your favor if you're waiting for the next maintenance window.

Three Questions for Business Leaders

You don't need to be a security engineer to drive action on this. Ask your IT or security team these three questions:

1. Do we run ServiceNow, and if so, is it cloud-hosted, self-hosted, or partner-hosted?

If it's self-hosted or partner-hosted, you need to know immediately whether the July 13 patch has been applied. Cloud-hosted instances should already be patched, but verification doesn't hurt.

2. If we're not fully patched, what's the timeline and who owns it?

This is not a "schedule it when we can" situation. Unauthenticated remote code execution under active exploitation is a drop-everything priority. If there's no clear owner and no clear timeline, that's a governance gap that will eventually cost you.

3. Do we have detection coverage for exploitation attempts?

The endpoint being targeted — `/assessment_thanks.do` — is documented. Ask whether your security monitoring tools are watching for anomalous traffic to that endpoint and whether alerts are in place. If you're relying solely on patching without monitoring, you're flying blind during the patching window.

The Bigger Picture

CVE-2026-6875 is a useful reminder of something that applies beyond this specific vulnerability: your security posture is only as strong as your slowest process. Excellent endpoint protection, rigorous access controls, and strong identity governance all matter — but if a business-critical platform has an unpatched critical flaw with active exploitation, all of those other controls are working around a gaping hole.

Security isn't just about having the right tools. It's about operational discipline — the processes, accountability structures, and monitoring that make sure known problems get fixed before attackers get there first.

If your organization would benefit from a clear-eyed assessment of where your most significant exposure points are, that's exactly what TrustPoint Cyber was built to do. We help business leaders understand what actually matters — without the noise, the vendor pitches, or the false sense of security that comes from checking a compliance box.

Reach out. The conversation is free. The risk of waiting is not.

Get Protected

Ready to strengthen your security?

TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.