unauthenticated remote code execution

A pair of critical remote code execution vulnerabilities in the ServiceNow AI Platform, CVE-2026-6875 and CVE-2026-0542, expose enterprise workflows and data to unauthenticated code execution across web interfaces, API endpoints, and automation modules integrated with AI-driven services.

CVE-2026-6875 is an unauthenticated sandbox escape and code injection flaw in the AI Platform’s script execution layer, assigned a critical CVSS 4.0 base score of 9.5 because it allows arbitrary server-side code to run beyond intended isolation boundaries. Active exploitation of CVE-2026-6875 has already been observed in the wild against vulnerable ServiceNow AI Platform instances that remain unpatched.

Critical CVE-2026-6875 turns unauthenticated sandbox escape into arbitrary server-side code execution beyond intended isolation

CVE-2026-0542 is a distinct remote code execution vulnerability in the ServiceNow AI sandbox with a critical 9.8 base score, enabling unauthenticated attackers to execute code within the sandbox context under certain platform and configuration conditions.

Together, these flaws erode trust in AI-mediated workflow automation by turning untrusted inputs processed in supposedly constrained environments into vectors for compromise of core ServiceNow instances, business records, and integrated IT service operations.

The technical root cause of CVE-2026-6875 is improper sandbox isolation in the AI Platform, allowing crafted inputs to escape the restricted execution environment and reach server-side scripting components that should have remained inaccessible to unauthenticated users.

Attackers can leverage the /assessment_thanks.do endpoint with specially constructed HTTP requests that invoke sandbox escape gadgets, converting benign-looking AI workflow interactions into pre-authentication code execution on the underlying ServiceNow application server.

CVE-2026-0542 arises from insufficient compartmentalization within the AI sandbox, where untrusted data flowing through AI processing pipelines can be transformed into executable code, giving adversaries RCE capabilities confined to the sandbox but still valuable for data theft and persistence.

Both vulnerabilities are exploitable remotely over network connections without user interaction, exposing any reachable, unpatched ServiceNow instances to unauthenticated probing, automated exploitation campaigns, and chained attacks that pivot from AI workflows into broader enterprise environments.

Successful exploitation of CVE-2026-6875 gives attackers arbitrary code execution on the ServiceNow application server, enabling full platform compromise, including manipulation of tickets and configuration items, alteration of workflow logic, and interference with IT service management and orchestration processes.

RCE within the sandbox via CVE-2026-0542 can expose sensitive data handled by AI-driven routines, such as business records, proprietary models, and embedded credentials, while providing a durable foothold for lateral movement and long-term persistence inside enterprise environments.

ServiceNow has acknowledged the AI Platform layer as broadly affected, issuing advisories that cover hosted SaaS deployments and self-hosted instances, and mapping fixes for CVE-2026-6875 and CVE-2026-0542 onto Zurich, Yokohama, and related release families to guide patching efforts.

Organizations are advised to rapidly inventory exposed instances, apply the prescribed platform updates, restrict access to AI-related endpoints, and enhance monitoring of sandbox activity so that exploitation attempts are detected quickly and the overall impact on confidentiality, integrity, and availability is minimized.

Failing to treat these vulnerabilities as emergency-level issues leaves AI-centric ServiceNow estates exposed to scalable attacks that can rapidly propagate across automated workflows and amplify damage.

You May Also Like

AI Spam Filters Remain Vulnerable to Old-School Text Salting Attacks

Invisible text tricks are outsmarting today’s most advanced AI spam filters, and the implications for email security are more alarming than you’d expect.

Hugging Face Data Breach Exposes Internal Datasets and Credentials as Users Face Security Risks

Sensitive API tokens, private model data, and internal credentials were compromised in a sweeping Hugging Face breach—and the full fallout may surprise you.

Nvidia Launches Synthetic Video Detector With Up to 92% Deepfake Accuracy

Shattering trust in video, Nvidia’s Synthetic Video Detector promises up to 92% deepfake-spotting accuracy—discover how this changes newsrooms and forensics next.

CrowdStrike Identifies Five Emerging Prompt Injection Attacks Targeting AI Systems

Beyond simple chatbot tricks, CrowdStrike’s latest taxonomy reveals five sophisticated prompt injection techniques silently dismantling AI defenses in ways defenders haven’t anticipated.