hacker-news · Crawled Jul 21, 2026

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

1 IoCs
Read original article ↗

AI Summary

Threat actors are actively exploiting a critical sandbox escape vulnerability, CVE-2026-6875, in the ServiceNow AI Platform to achieve unauthenticated remote code execution. The flaw allows attackers to compromise ServiceNow instances and connected proxy servers by targeting a pre-authentication endpoint. Exploitation uses HTTP POST requests to the '/assessment_thanks.do' endpoint, leveraging a sandbox-escape gadget to execute arbitrary code. ServiceNow has released patches for multiple versions and is enhancing sandbox security to restrict executable code types.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain assessment_thanks[.]do Details →