When Your Workflow Platform Becomes an Unauthenticated RCE Surface

On 13 July 2026 ServiceNow disclosed CVE-2026-6875, a CVSS 9.5 unauthenticated RCE in the AI Platform via sandbox escape on /assessment_thanks.do, with active exploitation from 17-19 July and a second gadget chain bypassing PoC-tuned defences. A six-point managed patching, virtual patching and MDR playbook for enterprise workflow platforms.

CALL IT DEV — Software, AI and dedicated tech teams — Casablanca | Madrid | Dubai

When Your Workflow Platform Becomes an Unauthenticated RCE Surface

On 13 July 2026 ServiceNow disclosed CVE-2026-6875, a CVSS 9.5 unauthenticated RCE in the AI Platform via sandbox escape on /assessment_thanks.do, with active exploitation from 17-19 July and a second gadget chain bypassing PoC-tuned defences. A six-point managed patching, virtual patching and MDR playbook for enterprise workflow platforms.

الأسئلة الشائعة

What did ServiceNow disclose on 13 July 2026 about the AI Platform?

On 13 July 2026 ServiceNow publicly disclosed CVE-2026-6875, a CVSS 9.5 unauthenticated remote code execution vulnerability in the ServiceNow AI Platform, exploitable by sending crafted HTTP requests to the /assessment_thanks.do endpoint via a sandbox escape. The flaw was privately reported by Searchlight Cyber on 1 April 2026. ServiceNow published fixes on the same day: Australia Patch 2, Brazil EA/GA, Zurich Patch 7b and Patch 9, and Yokohama Patch 12 Hot Fix 1b and Patch 13. By the weekend of 17-19 July 2026, coverage from The Hacker News, Help Net Security, SecurityWeek, BleepingComputer and SecurityAffairs reported active in-the-wild exploitation, and Defused documented a second sandbox-escape gadget chain that bypasses defences calibrated only against the public proof of concept. Impact extends to any proxy or integration server the instance can reach.

Why is an unauthenticated RCE on a workflow platform worse than a typical critical CVE?

Three properties compound the risk. First, identity blast radius: the workflow platform is federated to the identity provider, holds broadly-scoped service accounts, and often carries stored credentials for CRM, ERP and monitoring integrations, so a full compromise is effectively a compromise of an identity broker. Second, lateral proxy compromise: MID Servers and integration proxies reach into internal segments and cloud accounts, and the ServiceNow advisory explicitly states impact extends to connected proxy servers. Third, the exploit window has collapsed: private disclosure to Searchlight Cyber on 1 April 2026, coordinated fix on 13 July 2026, active exploitation within a week, and a second gadget chain in the wild that defeats mitigations tuned only to the first PoC — a quarterly patch cadence cannot defend that timeline.

What is a defensible emergency patch SLA for enterprise workflow platforms in 2026?

A defensible 2026 target is vendor critical advisory (CVSS >= 9) patched within 72 hours on internet-exposed instances, and CISA KEV listing patched within 24 to 72 hours in any case. Non-production environments are patched on the same clock because a partially patched estate is where second gadget chains land. Where patching in the window is genuinely blocked by regression risk, the compensating mitigation path — WAF rule, endpoint hard-block, temporary takedown or ACL restriction — is documented and executed inside the same clock. A quarterly change window that batches workflow-platform patches with generic business systems is no longer defensible against the disclosure-to-exploitation window observed on CVE-2026-6875.

How does virtual patching work in front of an unauthenticated workflow-platform endpoint?

Between disclosure and clean deployment, virtual patching buys time. For an unauthenticated RCE on a known endpoint such as /assessment_thanks.do in CVE-2026-6875, the compensating controls are unambiguous: at the WAF or reverse proxy, block or rate-limit the specific endpoints implicated by the advisory for unauthenticated origins, and require an authenticated session cookie or IP allow-listing for administrative surfaces. Because Defused documented a second gadget chain, block by endpoint and by exploitation payload shape, not only by the first published PoC signature. Virtual patching is not a substitute for the vendor fix; it is the bridge to it, deployed in production within four hours of a serious advisory when the run partner is competent.

How should MID Servers and integration proxies be hardened to shrink blast radius?

Tighten the trust boundary around MID Servers and integration proxies with three concrete moves. Place them in a dedicated network segment with restrictive egress that only permits the destinations declared in the integration inventory. Assign least-privilege service accounts on the target systems, scoped to the specific operations the integration performs, and rotate credentials on a defined cadence. Prohibit shared credentials between the workflow platform and other business applications so a compromised platform cannot hand the attacker keys to the ERP or the CRM. Combined with reducing internet exposure of administrative surfaces behind an identity-aware proxy, these controls shrink the blast radius of a platform compromise materially.

What should a buyer require of an outsourced IT or MDR partner for workflow platforms?

Six controls, written into the master service agreement and operational addendum: a live inventory of exposed workflow platforms and their unauthenticated endpoints reconciled weekly against an external attack-surface management scan; an emergency patch SLA in numeric terms tied to vendor CVSS-9+ advisories and CISA KEV listings; virtual-patching capability with WAF change management able to deploy a rule to production in four hours; exposure reduction on administrative surfaces via identity-aware proxy or VPN; 24/7 behavioural detection on the platform, MID Servers and connected proxies; and a rehearsed credential-rotation playbook for platform-connected integrations. Absence of that language signals the partner is running a ticket queue on top of the platform, not a managed-security posture.

How does Call IT Dev deliver the managed-patching playbook for workflow platforms from Morocco?

Call IT Dev operates cybersecurity, technical support and cloud infrastructure engagements from Morocco with nearshore EU-time-zone coverage, delivery in English, French, Spanish and Arabic, and a regulatory posture aligned with CNDP Law 09-08 and GDPR. The engagement applies the six-point playbook end-to-end: a living inventory of workflow / ITSM platforms reconciled to weekly ASM scans, an emergency patch SLA on the platform stack contractual in numeric terms, virtual patching at the WAF layer within four hours of a vendor advisory, exposure reduction on administrative surfaces, 24/7 behavioural detection on the platform and connected proxies, and a rehearsed credential-rotation playbook for MID Server and integration credentials.

CALL IT DEV — Software, AI and dedicated tech teams — Casablanca | Madrid | Dubai — contact@callitdev.com — +212-537-373777