ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
Threat intelligence firm Defused has confirmed that attackers are actively exploiting CVE-2026-6875, a severe pre-authentication remote code execution flaw in ServiceNow's AI Platform. This vulnerability allows unauthenticated users to bypass the script sandbox and execute arbitrary code on affected systems. Discovered by Searchlight Cyber researchers, the flaw was patched by ServiceNow in late June 2026, but exploitation in the wild began shortly after the public disclosure on July 13. Attackers are using payloads targeting the /assessment_thanks.do endpoint, employing a novel method for sandbox escape compared to the original proof-of-concept. Organizations running self-hosted instances should apply the latest security updates immediately.