hacker-news · Crawled Jul 21, 2026
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
1 IoCs
Read original article ↗
AI Summary
Threat actors are actively exploiting a critical sandbox escape vulnerability, CVE-2026-6875, in the ServiceNow AI Platform to achieve unauthenticated remote code execution. The flaw allows attackers to compromise ServiceNow instances and connected proxy servers by targeting a pre-authentication endpoint. Exploitation uses HTTP POST requests to the '/assessment_thanks.do' endpoint, leveraging a sandbox-escape gadget to execute arbitrary code. ServiceNow has released patches for multiple versions and is enhancing sandbox security to restrict executable code types.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | assessment_thanks[.]do | Details → |