Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

July 21, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Organizations using self-hosted ServiceNow AI Platform
Incident: Active exploitation of CVE-2026-6875 for unauthenticated remote code execution.
Impact: Complete system compromise and potential lateral movement to connected proxy servers.
Attacker: Unidentified threat actors
Analysis: CVE-2026-6875 allows unauthenticated attackers to bypass sandbox restrictions via the /assessment_thanks.do endpoint. This flaw permits arbitrary code execution, potentially leading to a total compromise of the platform and linked proxy servers. Exploitation is currently active, specifically targeting unpatched self-hosted instances.
Recommendations: Apply the latest ServiceNow security patches for Brazil, Australia, Zurich, and Yokohama versions immediately.; Audit web server logs for suspicious HTTP POST requests targeting the /assessment_thanks.do endpoint.; Implement strict network access controls to limit exposure of the AI platform’s management interfaces.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *