Find notable cyber news and cases, enriched with sources, timelines, and signals.

ServiceNow AI Platform pre-auth sandbox-escape RCE (CVE-2026-6875, actively exploited)

Vulnerability
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-6875 is now actively exploited in the wild against the ServiceNow AI Platform, exposing unauthenticated systems to remote code execution. The flaw is a pre-auth sandbox-escape RCE that lets attackers reach code execution after breaking out of the platform sandbox. ServiceNow issued July 13th patches for hosted and self-hosted instances, but researchers observed the first attack attempts on Friday and confirmed abuse over the weekend.

Related Happenings

CISA KEV mitigation for BeyondTrust CVE-2026-1731

Advisory/Mitigation
H score46 First: 20.02.2026 19:02 Last: 20.02.2026 19:02 Sources 1

About this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...

BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave

Exploitation Wave
H score76 First: 12.02.2026 23:34 Last: 12.02.2026 23:34 Sources 1

About this happening: CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...

IBM API Connect CVE-2025-13915 mitigation guidance

Advisory/Mitigation
H score42 First: 31.12.2025 12:34 Last: 31.12.2025 12:34 Sources 1

About this happening: IBM told customers to upgrade IBM API Connect to address CVE-2025-13915, a critical authentication bypass that can let unauthenticated attackers reach exposed...

Timeline

  1. 20.07.2026 12:29 1 articles · 15h ago

    ServiceNow releases CVE-2026-6875 security updates

    Mitigation Patch Update

    ServiceNow addressed the flaw across hosted instances and released CVE-2026-6875 security updates for self-hosted instances, urging customers to upgrade to a patched release as soon as possible.

    Show sources
  2. 20.07.2026 12:29 1 articles · 15h ago

    Attackers begin exploiting CVE-2026-6875

    Exploitation Observed

    Defused security researchers observed first exploitation attempts on Friday, and the payloads targeted the same pre-auth sink documented at /assessment_thanks.do while reaching code execution through a different sandbox-escape route.

    Show sources
  3. 20.07.2026 12:29 2 articles · 15h ago

    Researchers confirm in-the-wild exploitation of CVE-2026-6875

    Initial Disclosure

    Defused confirmed in-the-wild exploitation of CVE-2026-6875 in the ServiceNow AI Platform on Saturday, while ServiceNow's advisory still said it was not currently aware of exploitation against ServiceNow instances.

    Show sources