ServiceNow has released security updates for a critical vulnerability in its AI platform after researchers published a proof of concept demonstrating pre-authentication remote code execution. The flaw, tracked as CVE-2026-6875, is a sandbox escape issue that could allow an unauthenticated attacker to run code within a vulnerable ServiceNow instance. Researchers from Assetnote at Searchlight Cyber disclosed the vulnerability in a technical report titled “Smashing the ServiceNow Sandbox: Pre-Authentication RCE.” According to Searchlight Cyber researchers, successful exploitation could lead to a full compromise of a ServiceNow instance, including access to data stored in tables, the ability to create administrator accounts, and...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!