ServiceNow security patch release for CVE-2026-6875
Security Patch Release
Summary
Hide ▲
Show ▼
ServiceNow released CVE-2026-6875 security updates for the ServiceNow AI Platform, covering hosted and self-hosted instances. The patch addresses a pre-auth sandbox-escape RCE that can let unauthenticated threat actors execute code remotely. Customers who have not upgraded are being told to move to a patched release as soon as possible.
Related Happenings
WordPress core pre-auth RCE patch bundle (6.9.5, 7.0.2)
Security Patch Release
H score62
First: 18.07.2026 00:20
Last: 18.07.2026 00:20
Sources 1
About this happening:
WordPress Core shipped 6.9.5 and 7.0.2 on July 17, 2026 to close a pre-auth RCE that can be triggered by an anonymous request on a default install with n...
WordPress core pre-auth RCE patch bundle (6.9.5, 7.0.2)
Security Patch ReleaseAbout this happening: WordPress Core shipped 6.9.5 and 7.0.2 on July 17, 2026 to close a pre-auth RCE that can be triggered by an anonymous request on a default install with n...
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch Release
H score29
First: 14.07.2026 16:48
Last: 14.07.2026 16:48
Sources 1
About this happening:
RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch ReleaseAbout this happening: RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
Dify security patch release for CVE-2026-41947
Security Patch Release
H score34
First: 22.06.2026 19:13
Last: 22.06.2026 19:13
Sources 1
About this happening:
Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
Dify security patch release for CVE-2026-41947
Security Patch ReleaseAbout this happening: Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
SimpleHelp security update for CVE-2026-48558
Security Patch Release
H score65
First: 15.06.2026 23:06
Last: 15.06.2026 23:06
Sources 1
About this happening:
SimpleHelp released 5.5.16 and 6.0 RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw in SimpleHelp remote management software th...
SimpleHelp security update for CVE-2026-48558
Security Patch ReleaseAbout this happening: SimpleHelp released 5.5.16 and 6.0 RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw in SimpleHelp remote management software th...
TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926
Security Patch Release
H score45
First: 22.05.2026 11:19
Last: 22.05.2026 11:19
Sources 1
About this happening:
TrendAI released Apex One security updates after confirming a zero-day had been exploited in the wild, leaving on-premises installations at risk until patched....
TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926
Security Patch ReleaseAbout this happening: TrendAI released Apex One security updates after confirming a zero-day had been exploited in the wild, leaving on-premises installations at risk until patched....
Timeline
-
20.07.2026 12:29 2 articles · 15h ago
ServiceNow releases CVE-2026-6875 security updates for hosted and self-hosted instances
Mitigation Patch UpdateServiceNow addressed the CVE-2026-6875 flaw across hosted instances and released security updates for self-hosted instances on July 13, telling customers who had not already done so to upgrade to a patched release as soon as possible.
Show sources
- Critical ServiceNow code execution flaw now exploited in attacks — www.bleepingcomputer.com — 20.07.2026 12:29
- Critical ServiceNow code execution flaw now exploited in attacks — www.bleepingcomputer.com — 20.07.2026 12:29