socradar.io 7/21/2026, 12:33:12 PM · external

CVE-2026-6875 Hits ServiceNow AI Platform

CVE-2026-6875 Hits ServiceNow AI Platform
Developing story vulnerability 7 articles tracked
Critical ServiceNow AI platform RCE flaw (CVE-2026-6875) exploited in the wild
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

THE blog discusses CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, which enables unauthenticated attackers to execute code under certain conditions. ServiceNow has provided necessary updates for both hosted and self-hosted instances. The vulnerability, rated with a CVSS score of 9.5, involves a sandbox escape that may allow access to sensitive data and administrative capabilities.

Security teams are urged to confirm their patch status and monitor unusual activities related to the vulnerability. ServiceNow's introduction of Guarded Script aims to enhance security in sandboxed contexts. Organizations are advised to prioritize validations and patch updates, especially in self-hosted environments.

View Primary Source Via socradar.io

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline