A critical pre-authentication remote code execution vulnerability (CVE-2026-6875) in the ServiceNow AI Platform allows unauthenticated attackers to escape the script sandbox via code injection. The article does not provide a CVSS score, specific affected version ranges, a fixed version number, or a workaround. Threat intelligence indicates active exploitation is occurring in the wild.
Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance. The vulnerability was unearthed by Searchlight Cyber researchers and reported to ServiceNow in early April 2026. The … More → The post ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) appeared first on Help Net Security .