ServiceNow Sandbox RCE Under Active Exploit u2014 What African CISOs Need to Know

Defused spotted it first: someone is actively exploiting a pre-auth sandbox escape in ServiceNow, tracked as CVE-2026-6875. ServiceNow patched it last week. The exploit code is public. And the attackers are already changing their methods faster than anyone expected.

What happened

Threat intel firm Defused reported on July 20 that CVE-2026-6875, a sandbox escape in ServiceNow that allows remote code execution without authentication, is being actively exploited. ServiceNow shipped a patch last week, but researchers at Searchlight Cyber had already published a proof of concept, and the exploit code is circulating.

Defused CEO Simo Kohonen told CSO Online they have seen the exploit in the wild. One attacker, one incident so far. But what caught his attention was how fast the attacker adapted. ServiceNow put five mitigations in place, which “neutered” the original attack method. The attacker responded by tweaking their approach. “We are seeing a lot of attack variations, much more so than a year ago, for the same vulnerability,” Kohonen said. Attackers have more tools to build their own exploits now, and they are using them.

Why this matters for African enterprises

ServiceNow runs in a lot of African financial institutions, telcos, and government agencies. It holds HR records, CMDB asset inventories, and the ticketing system itself. A sandbox escape inside that tenant can turn into a bridge to the corporate network through MID Server integrations.

Frank Dickson, group VP for security at IDC, put it this way: “A compromise that starts in the cloud tenant can end up inside the corporate network, turning a SaaS incident into an on-premises one. And because ServiceNow frequently houses HR records, CMDB asset data, and the ticketing system itself, an attacker sitting inside it may have visibility into how the incident response team is tracking the incident.”

That is a nasty information asymmetry for any security team. For African teams running lean, it is the kind of gap that turns a recoverable breach into a painful one.

The sandbox failed

Noah Kenney, principal consultant at Digital 520, said it plainly: the bug is not really about ServiceNow having a critical vulnerability. It is about the sandbox breaking. The containment layer built specifically to run untrusted AI-driven code safely is what failed. CISOs have been told for years that sandboxes make enterprise AI safe to deploy. This incident says otherwise.

Kenney suggests CISOs start asking every AI-enabled SaaS vendor exactly how that sandbox boundary is architected and tested, before the next version of this story breaks somewhere else.

AI is making the blast radius bigger

Aman Mahapatra, chief strategy officer at Tribeca Softtech, pointed out that a ServiceNow compromise in 2026 gives an attacker access to whatever AI agents are running inside that instance, along with their capability tokens, service accounts, and delegated permissions.

“The blast radius of a ServiceNow compromise in 2026 is meaningfully larger than the same compromise would have been in 2023, and most enterprise security programs have not caught up to that shift,” he said.

This is the pattern across enterprise SaaS now. Vendors ship AI features faster than anyone updates the threat models. The AI layer becomes the softest part of the hardest targets. Kenney: “The real question for a CISO is how many of your critical platforms shipped an AI feature in the past year, and whether a single person in your organization can tell you what that did to the pre-auth attack surface. Most cannot, and that is the actual exposure.”

What you should do today

Patch ServiceNow immediately if you have not already. The patch is available for both self-hosted and ServiceNow-hosted instances. Do not wait for the next maintenance window.

Do not assume your detection rules will catch this. The attackers are varying their techniques. Signature-based detections keyed to the original PoC will miss the adapted versions.

Review your MID Server integrations. Every ServiceNow MID Server that connects to an on-premises system is a potential lateral movement path. Segment the traffic and monitor it.

Audit your AI agent permissions. Every capability token and service account tied to AI agents in ServiceNow should have the minimum permissions it actually needs. In a sandbox escape, those tokens are prime targets.

Start asking your SaaS vendors the hard questions about their sandbox architecture. How is it tested? What happens when it fails? If they cannot answer clearly, that tells you something.

The network is where it crosses over

A SaaS sandbox escape that turns into a network breach shifts the focus back to where the real boundary lives. Cloud security posture management and patching are necessary but not sufficient. The network layer is where containment happens. eHawu gives African enterprises the visibility and control to detect lateral movement from compromised cloud tenants before it reaches critical on-premises systems.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *