Three maximum-severity bugs in the ServiceNow AI Platform can be exploited without authentication.
Reco tracks a long-running campaign harvesting records from over-permissioned SaaS portals.
CVE-2026-6875 lets attackers bypass the ServiceNow script sandbox through a JavaScript override technique, with exploitation already in the wild.
Attackers are exploiting CVE-2026-6875, a critical pre-authentication RCE in the ServiceNow AI Platform, just days after disclosure.
ServiceNow disclosed that threat actors exploited an unpatched configuration flaw to query a subset of customer instances before a security…