ServiceNow AI Platform pre-auth sandbox-escape RCE (CVE-2026-6875, actively exploited)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-6875 is now actively exploited in the wild against the ServiceNow AI Platform, exposing unauthenticated systems to remote code execution. The flaw is a pre-auth sandbox-escape RCE that lets attackers reach code execution after breaking out of the platform sandbox. ServiceNow issued July 13th patches for hosted and self-hosted instances, but researchers observed the first attack attempts on Friday and confirmed abuse over the weekend.
Related Happenings
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/Mitigation
H score46
First: 20.02.2026 19:02
Last: 20.02.2026 19:02
Sources 1
About this happening:
CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/MitigationAbout this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave
Exploitation Wave
H score76
First: 12.02.2026 23:34
Last: 12.02.2026 23:34
Sources 1
About this happening:
CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...
BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave
Exploitation WaveAbout this happening: CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...
IBM API Connect CVE-2025-13915 mitigation guidance
Advisory/Mitigation
H score42
First: 31.12.2025 12:34
Last: 31.12.2025 12:34
Sources 1
About this happening:
IBM told customers to upgrade IBM API Connect to address CVE-2025-13915, a critical authentication bypass that can let unauthenticated attackers reach exposed...
IBM API Connect CVE-2025-13915 mitigation guidance
Advisory/MitigationAbout this happening: IBM told customers to upgrade IBM API Connect to address CVE-2025-13915, a critical authentication bypass that can let unauthenticated attackers reach exposed...
Timeline
-
20.07.2026 12:29 1 articles · 15h ago
ServiceNow releases CVE-2026-6875 security updates
Mitigation Patch UpdateServiceNow addressed the flaw across hosted instances and released CVE-2026-6875 security updates for self-hosted instances, urging customers to upgrade to a patched release as soon as possible.
Show sources
- Critical ServiceNow code execution flaw now exploited in attacks — www.bleepingcomputer.com — 20.07.2026 12:29
-
20.07.2026 12:29 1 articles · 15h ago
Attackers begin exploiting CVE-2026-6875
Exploitation ObservedDefused security researchers observed first exploitation attempts on Friday, and the payloads targeted the same pre-auth sink documented at /assessment_thanks.do while reaching code execution through a different sandbox-escape route.
Show sources
- Critical ServiceNow code execution flaw now exploited in attacks — www.bleepingcomputer.com — 20.07.2026 12:29
-
20.07.2026 12:29 2 articles · 15h ago
Researchers confirm in-the-wild exploitation of CVE-2026-6875
Initial DisclosureDefused confirmed in-the-wild exploitation of CVE-2026-6875 in the ServiceNow AI Platform on Saturday, while ServiceNow's advisory still said it was not currently aware of exploitation against ServiceNow instances.
Show sources
- Critical ServiceNow code execution flaw now exploited in attacks — www.bleepingcomputer.com — 20.07.2026 12:29
- Critical ServiceNow code execution flaw now exploited in attacks — www.bleepingcomputer.com — 20.07.2026 12:29