ServiceNow has released security updates for a critical vulnerability in its AI platform after researchers published a proof of concept demonstrating pre-authentication remote code execution. The flaw, tracked as CVE-2026-6875, is a sandbox escape issue that could allow an unauthenticated attacker to run code within a vulnerable ServiceNow instance. Researchers from Assetnote at Searchlight Cyber disclosed the vulnerability in a technical report titled “Smashing the ServiceNow Sandbox: Pre-Authentication RCE.” According to Searchlight Cyber researchers, successful exploitation could lead to a full compromise of a ServiceNow instance, including access to data stored in tables, the ability to create administrator accounts, and...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!