THE blog discusses CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, which enables unauthenticated attackers to execute code under certain conditions. ServiceNow has provided necessary updates for both hosted and self-hosted instances. The vulnerability, rated with a CVSS score of 9.5, involves a sandbox escape that may allow access to sensitive data and administrative capabilities.
Security teams are urged to confirm their patch status and monitor unusual activities related to the vulnerability. ServiceNow's introduction of Guarded Script aims to enhance security in sandboxed contexts. Organizations are advised to prioritize validations and patch updates, especially in self-hosted environments.