
Hackers Exploit ServiceNow Sandbox Escape Flaw for Pre-Auth Remote Code Execution
Threat actors have begun actively exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform that allows unauthenticated remote code execution through a script sandbox escape. Threat intelligence firm Defused confirmed the first exploitation attempts surfaced on Friday, with active in-the-wild. CVE-2026-6875 is a code injection flaw that lets attackers escape ServiceNow’s script sandbox […]
The post Hackers Exploit ServiceNow Sandbox Escape Flaw for Pre-Auth Remote Code Execution appeared first on Cyber Security News.