cd /news/artificial-intelligence/servicenow-pre-auth-rce-exploited-in… · home topics artificial-intelligence article
[ARTICLE · art-65654] src=helpnetsecurity.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

Attackers are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. The flaw, discovered by Searchlight Cyber and reported in April 2026, allows unauthenticated attackers to escape ServiceNow's script sandbox and execute arbitrary code on targeted instances.

read1 min views1 publishedJul 20, 2026

Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance. The vulnerability was unearthed by Searchlight Cyber researchers and reported to ServiceNow in early April 2026. The … More

The post ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) appeared first on Help Net Security.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @servicenow 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/servicenow-pre-auth-…] indexed:0 read:1min 2026-07-20 ·