news.mlab.sh
Back to the feed
vulnerability

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Critical
Summary

A critical security vulnerability in ServiceNow's AI Platform is being actively exploited, allowing unauthenticated code execution and potentially a complete compromise of ServiceNow instances. ServiceNow has released patches to address the issue, and customers should apply them immediately to mitigate the risk.

A recently disclosed critical security vulnerability in ServiceNow's AI Platform is being actively exploited, allowing unauthenticated code execution and potentially a complete compromise of ServiceNow instances. ServiceNow has released patches to address the issue, and customers should apply them immediately to mitigate the risk. Defused Cyber reported the vulnerability on April 1, 2026, and has observed in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5). Searchlight Cyber further detailed the issue, noting that it enables a complete compromise of the ServiceNow instance and all connected proxy servers. The vulnerability targets the same pre-authentication endpoint ("/assessment_thanks.do") using HTTP POST requests, although the sandbox-escape gadget leads to the same code execution primitive by a different route documented in the proof-of-concept (PoC) exploit. ServiceNow is also enhancing instance security by severely restricting the type of code that can run in sandbox contexts. Customers of self-hosted versions are advised to apply the fixes, if not already, to counter the threat.

Read the full article at The Hacker News