Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
ID: 5dc54e95-d82c-516b-aa5c-9044b11feaac
STIX ID: report--5dc54e95-d82c-516b-aa5c-9044b11feaac
Feed Name: Security Affairs
A critical unauthenticated RCE (CVE-2026-6875) in ServiceNow’s GlideRecord query API was disclosed and rapidly weaponized: attackers exploit a sandbox-escape gadget chain (via javascript: prefixed inputs, gs.include and Object.clone override) against the /assessment_thanks.do sink to achieve full instance compromise and proxy server command execution; ServiceNow patched cloud instances quickly and released fixes for self-hosted customers, but active exploitation against unpatched hosts has been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
