FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

CVE-2026-6875: Pre-Authentication RCE and Sandbox Escape in ServiceNow AI Platform

CVE-2026-6875 is a critical pre-authentication code injection vulnerability in the ServiceNow AI Platform scripting sandbox. The flaw allows unauthenticated attackers to achieve a full sandbox escape, leading to Remote Code Execution (RCE) on the underlying host. Exploitation enables OS command execution and the creation of unauthorized administrative accounts. Furthermore, attackers can pivot from the ServiceNow cloud tenant into internal corporate networks via MID Server integrations. While patches were released on July 14, 2026, active exploitation began July 17, 2026, with threat actors utilizing adaptive payloads to bypass signature-based mitigations and the containment layer.

Sandbox Escape Vulnerability in Anthropic's Claude Cowork for Windows

Security researcher Armadin has identified a multi-step attack chain capable of executing a sandbox escape within Anthropic's Claude Cowork for Windows. The vulnerability exploits two distinct weaknesses to bypass the application's Windows-specific isolation layer, enabling an AI agent or malicious input to interact directly with the host operating system. This exploit includes a network sandbox bypass, facilitating unauthorized external communication and the silent exfiltration of sensitive host data, including API keys and filesystem contents. While Anthropic disputes the practical risk and severity, the findings highlight critical boundary failures in AI agent architectures, where functional deployment speed may compromise essential host-level security controls.


LINK COPIED TO CLIPBOARD