Expert In the Cloud • 7h
CVE-2026-6875: Critical Pre-Authentication RCE in ServiceNow AI Platform
CVE-2026-6875 is a critical pre-authentication vulnerability in the ServiceNow AI Platform that allows unauthenticated attackers to execute arbitrary code via a scripting sandbox escape. By leveraging code injection to bypass containment layers, attackers achieve Remote Code Execution (RCE) within the platform. The vulnerability is actively exploited in the wild, with threat actors utilizing polymorphic payloads to evade multiple vendor-issued mitigations. The primary risk involves the compromise of privileged AI agent capability tokens and the potential for lateral movement from cloud-hosted SaaS environments to on-premises corporate networks through MID Server integrations, threatening sensitive HR, CMDB, and ticketing data.