Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
ID: 6093797f-d38c-587a-8312-9d7cc2324f5b
STIX ID: report--6093797f-d38c-587a-8312-9d7cc2324f5b
Feed Name: GBHackers
A critical pre-authentication remote code execution vulnerability (CVE-2026-6875) in the ServiceNow AI Platform is being actively exploited in the wild; attackers are abusing a pre-auth endpoint (/assessment_thanks.do) and sandbox-escape techniques involving Script Includes to execute code, potentially enabling data theft, admin-user creation, and lateral movement. ServiceNow has released patches and mitigations; organizations are advised to apply fixes, monitor suspicious requests to the endpoint (particularly sysparm_assessable_type and javascript: expressions), and investigate anomalous Script Include, MID Server, and administrative activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
