CVE Tools

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

Help Net SecurityBy Zeljka Zorz

Reported exploitedServiceNow AI Platform

Our summary

Threat intelligence firm Defused has confirmed that attackers are actively exploiting CVE-2026-6875, a severe pre-authentication remote code execution flaw in ServiceNow's AI Platform. This vulnerability allows unauthenticated users to bypass the script sandbox and execute arbitrary code on affected systems. Discovered by Searchlight Cyber researchers, the flaw was patched by ServiceNow in late June 2026, but exploitation in the wild began shortly after the public disclosure on July 13. Attackers are using payloads targeting the /assessment_thanks.do endpoint, employing a novel method for sandbox escape compared to the original proof-of-concept. Organizations running self-hosted instances should apply the latest security updates immediately.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store