Expert In the Cloud • 2h
CVE-2026-6875: Pre-Authentication RCE and Sandbox Escape in ServiceNow AI Platform
CVE-2026-6875 is a critical pre-authentication code injection vulnerability in the ServiceNow AI Platform scripting sandbox. The flaw allows unauthenticated attackers to achieve a full sandbox escape, leading to Remote Code Execution (RCE) on the underlying host. Exploitation enables OS command execution and the creation of unauthorized administrative accounts. Furthermore, attackers can pivot from the ServiceNow cloud tenant into internal corporate networks via MID Server integrations. While patches were released on July 14, 2026, active exploitation began July 17, 2026, with threat actors utilizing adaptive payloads to bypass signature-based mitigations and the containment layer.