Exploitation of enterprise SaaS platforms is now arriving within days of the patch, not the disclosure. ServiceNow shipped a fix for CVE-2026-6875, a sandbox-escape flaw in its AI Platform that lets an unauthenticated attacker run arbitrary code, on July 13, 2026. Threat intelligence firm Defused observed exploitation attempts in the wild by July 18 and 19, roughly five days later. Researchers at Searchlight Cyber, who reported the flaw to ServiceNow and published technical details around the patch release, found the captured attack payload matched their own proof-of-concept method closely enough that a second, distinct sandbox-escape technique was also confirmed active.
Why it matters: ServiceNow instances sit at the center of IT service management, HR case handling, and increasingly agentic AI workflows for large enterprises, so an unauthenticated code-execution path is a direct line into whatever data and integrations that instance touches. ServiceNow says it has found no evidence the activity affects instances it hosts directly, which narrows the immediate exposure to self-hosted deployments that have not yet applied the July 13 update.
The compressed timeline here fits a broader pattern this publication has tracked across other platforms: the gap between a vendor patch and working exploitation in the wild has been collapsing across enterprise software generally, and a five-day window from fix to confirmed attack is consistent with that trend rather than an outlier. For security leaders, the operational takeaway is that publishing a proof-of-concept alongside patch guidance, even for defensive research purposes, now functions as a starting gun. Self-hosted ServiceNow customers should treat the July 13 update as urgent rather than routine, verify sandbox-escape detection coverage against both confirmed exploitation techniques, and confirm whether any AI Platform instance is reachable from outside a trusted network boundary before assuming the patch alone closes the exposure.