RESEARCHERS have identified a critical remote code execution (RCE) vulnerability in ServiceNow, tracked as CVE-2026-6875, allowing attackers to execute arbitrary code on self-hosted instances. Disclosed by Searchlight Cyber on July 14, 2026, the flaw was exploited in the wild shortly after. The vulnerability stems from an oversight in ServiceNow's GlideRecord API, where unauthenticated user-supplied input can be manipulated.
Despite initial protections, significant gaps in the sandboxing measures were exploited, allowing attackers to execute commands and access sensitive data. ServiceNow released patches on July 13 and implemented additional security measures in response. Users are urged to apply patches immediately to mitigate risks.