# ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

> Source: <https://www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/>
> Published: 2026-07-20 14:32:31+00:00

Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance. The vulnerability was unearthed by Searchlight Cyber researchers and reported to ServiceNow in early April 2026. The … [More ](https://www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/)

The post [ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)](https://www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/) appeared first on [Help Net Security](https://www.helpnetsecurity.com).
