{"slug": "servicenow-pre-auth-rce-exploited-in-the-wild-cve-2026-6875", "title": "ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)", "summary": "Attackers are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. The flaw, discovered by Searchlight Cyber researchers and reported to ServiceNow in early April 2026, allows unauthenticated attackers to escape ServiceNow's script sandbox and execute arbitrary code on targeted instances.", "body_md": "Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance. The vulnerability was unearthed by Searchlight Cyber researchers and reported to ServiceNow in early April 2026. The … [More ](https://www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/)\n\nThe post [ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)](https://www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/) appeared first on [Help Net Security](https://www.helpnetsecurity.com).", "url": "https://wpnews.pro/news/servicenow-pre-auth-rce-exploited-in-the-wild-cve-2026-6875", "canonical_source": "https://www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/", "published_at": "2026-07-20 14:32:31+00:00", "updated_at": "2026-07-20 14:58:47.604257+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-infrastructure"], "entities": ["ServiceNow", "Defused", "Searchlight Cyber", "CVE-2026-6875"], "alternates": {"html": "https://wpnews.pro/news/servicenow-pre-auth-rce-exploited-in-the-wild-cve-2026-6875", "markdown": "https://wpnews.pro/news/servicenow-pre-auth-rce-exploited-in-the-wild-cve-2026-6875.md", "text": "https://wpnews.pro/news/servicenow-pre-auth-rce-exploited-in-the-wild-cve-2026-6875.txt", "jsonld": "https://wpnews.pro/news/servicenow-pre-auth-rce-exploited-in-the-wild-cve-2026-6875.jsonld"}}