CVE-2026-6875 lets attackers bypass the ServiceNow script sandbox through a JavaScript override technique, with exploitation already in the wild.