logo

Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875

ID: 5dc54e95-d82c-516b-aa5c-9044b11feaac

STIX ID: report--5dc54e95-d82c-516b-aa5c-9044b11feaac

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Pierluigi Paganini

...
...

A critical unauthenticated RCE (CVE-2026-6875) in ServiceNow’s GlideRecord query API was disclosed and rapidly weaponized: attackers exploit a sandbox-escape gadget chain (via javascript: prefixed inputs, gs.include and Object.clone override) against the /assessment_thanks.do sink to achieve full instance compromise and proxy server command execution; ServiceNow patched cloud instances quickly and released fixes for self-hosted customers, but active exploitation against unpatched hosts has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.