Back to feed
Dev.to
Dev.to
7/22/2026
The original title is: "CVE-2022-6875: ServiceNow AI Platform Sandbox Escape Under Active Exploitation"

The original title is: "CVE-2022-6875: ServiceNow AI Platform Sandbox Escape Under Active Exploitation"

Original: CVE-2026-6875: ServiceNow AI Platform Sandbox Escape Under Active Exploitation

Short summary

CVE-2026-6875 is a critical (CVSS 9.5) pre-auth sandbox escape in the ServiceNow AI Platform enabling unauthenticated arbitrary code execution, actively exploited since July 21, 2026. Successful exploitation compromises the entire ServiceNow instance and connected proxy servers, exposing ITSM data, credentials, and integration secrets. Patches have been available since June across all release trains; self-hosted customers should apply them immediately.

  • Critical pre-auth RCE in ServiceNow AI Platform (CVSS 9.5) under active exploitation
  • Full instance compromise exposes ITSM data, credentials, and downstream integrations
  • Apply June 2026 patches immediately across all release trains

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more