CRITICAL: ServiceNow AI Platform Pre-Auth RCE (CVE-2026-6875) Under Active Attack
A critical unauthenticated remote code execution flaw in the ServiceNow AI Platform, CVE-2026-6875, is under active attack after threat actors weaponized a sandbox escape against the /assessment_thanks.do endpoint. Scored 9.5 on CVSS 4.0, it lets attackers run code with no credentials. Patches reached hosted instances in April and self hosted customers in June, and every unpatched instance is now a live target.