SECURITYTHE HACKER NEWS
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Threat actors are exploiting a critical sandbox escape vulnerability (CVE-2026-6875) in ServiceNow AI Platform, allowing unauthenticated users to execute arbitrary code. Defused Cyber reported active exploitation of the flaw, which carries a CVSS score of 9.5. Patches for the vulnerability have been released.
Related Signal
Adjacent reporting
- Critical ServiceNow code execution flaw now exploited in attacks
- Google Fixes Critical RCE Flaw in AI-Based Antigravity Tool
- Three critical Fortinet sandbox bugs splattered by unknown attackers
- Vuln in Google’s Antigravity AI agent manager could escape sandbox, give attackers remote code execution
- Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape
- Max severity Flowise RCE vulnerability now exploited in attacks