ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
Reported exploitedServiceNow AI PlatformOur summary
Threat intelligence firm Defused has confirmed that attackers are actively exploiting CVE-2026-6875, a severe pre-authentication remote code execution flaw in ServiceNow's AI Platform. This vulnerability allows unauthenticated users to bypass the script sandbox and execute arbitrary code on affected systems. Discovered by Searchlight Cyber researchers, the flaw was patched by ServiceNow in late June 2026, but exploitation in the wild began shortly after the public disclosure on July 13. Attackers are using payloads targeting the /assessment_thanks.do endpoint, employing a novel method for sandbox escape compared to the original proof-of-concept. Organizations running self-hosted instances should apply the latest security updates immediately.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.