보안뉴스 아카이브
긴급도 34/100 심각도 미평가 · 미평가 악용확률 99.5% CWE-94

CVE-2026-6875

Qualys 위협 인텔 · 심각도 5/5 · QID 734864 · CGI
공개 익스플로잇 측면이동 쉬운 악용 대량 데이터 유출 서비스 거부 원격코드실행
  • CVSS Temporal 8.8 (현재 위협 반영)
  • 익스플로잇 성숙도: PoC (2/4)
  • 공격 위치: 원격
  • 패치: 가능
  • PCI-DSS 관련
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform.


ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners.




Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances.




We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

NVD 상세 ↗   참고 링크 ↗

이 취약점을 다룬 기사 (2)

← 취약점 목록