ServiceNow AI Platform の脆弱性 CVE-2026-6875:サンドボックス・エスケープと RCE に関する注意喚起

Critical ServiceNow AI Platform Flaw Allows Unauthenticated Attackers to Escape Sandbox and Execute Remote Code

2026/07/14 gbhackers — ServiceNow が公表したのは、同社の AI Platform に存在する重大なリモート・コード実行の脆弱性に対処するための、セキュリティ更新のリリースである。この脆弱性 CVE-2026-6875 を悪用する未認証の攻撃者は、影響を受ける ServiceNow 環境内でのコード実行の可能性を得る。この問題は、ServiceNow AI Platform に影響を及ぼすサンドボックス・エスケープの欠陥であると説明されている。

Continue reading “ServiceNow AI Platform の脆弱性 CVE-2026-6875:サンドボックス・エスケープと RCE に関する注意喚起”