Answer in brief
CVE-2026-6875 records a Critical severity (CVSS 9.5) vulnerability in Sandbox Escape in ServiceNow AI Platform. The current sources do not mark it as known exploited. The current feed maps ServiceNow/ServiceNow AI Platform (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps ServiceNow/ServiceNow AI Platform (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| ServiceNow/ServiceNow AI Platformgeneric | >=0 <Australia Patch 2 || >=0 <Yokohama Patch 12 Hot Fix 1b || >=0 <Yokohama Patch 13 || >=0 <Zurich Patch 7b || >=0 <Zurich Patch 9 || >=0 <Brazil EA || >=0 <Brazil GA | Australia Patch 2, Yokohama Patch 12 Hot Fix 1b, Yokohama Patch 13, Zurich Patch 7b, Zurich Patch 9, Brazil EA, Brazil GA |
Published upstream
Jul 13, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 13, 2026
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-6875 records a Critical severity (CVSS 9.5) vulnerability in Sandbox Escape in ServiceNow AI Platform. The current sources do not mark it as known exploited. The current feed maps ServiceNow/ServiceNow AI Platform (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps ServiceNow/ServiceNow AI Platform (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| ServiceNow/ServiceNow AI Platformgeneric | >=0 <Australia Patch 2 || >=0 <Yokohama Patch 12 Hot Fix 1b || >=0 <Yokohama Patch 13 || >=0 <Zurich Patch 7b || >=0 <Zurich Patch 9 || >=0 <Brazil EA || >=0 <Brazil GA | Australia Patch 2, Yokohama Patch 12 Hot Fix 1b, Yokohama Patch 13, Zurich Patch 7b, Zurich Patch 9, Brazil EA, Brazil GA |
Published upstream
Jul 13, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 13, 2026
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Quoted source text, attributed separately from HOL analysis.