Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
RoundupServiceNow AI PlatformHugging Face platformOur summary
This week saw significant security incidents involving ServiceNow and Hugging Face. A critical pre-authentication remote code execution vulnerability (CVE-2026-6875) in the ServiceNow AI Platform is currently being exploited in the wild, enabling unauthenticated attackers to execute arbitrary code. Meanwhile, Hugging Face reported a breach attributed to an autonomous AI agent that gained unauthorized access to internal datasets and credentials. These events underscore the growing risks associated with AI platforms and the importance of timely patching and robust security measures.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.