Critical

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

Help Net Security
Actively Exploited

Overview

A critical vulnerability in the ServiceNow AI Platform, identified as CVE-2026-6875, is being actively exploited by attackers. This pre-authentication code injection flaw allows unauthenticated users to escape the platform's script sandbox and execute arbitrary code on targeted instances. Researchers from Searchlight Cyber discovered this vulnerability and reported it to ServiceNow in early April 2026. The exploitation of this vulnerability poses significant risks to organizations using the ServiceNow AI Platform, as it could lead to unauthorized access and control over sensitive workflows and data. Companies are urged to take immediate action to safeguard their systems against potential attacks.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: ServiceNow AI Platform
  • Action Required: Organizations should apply any available patches from ServiceNow and review their security configurations to limit unauthorized access.
  • Timeline: Disclosed on April 2026

Original Article Summary

Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance. The vulnerability was unearthed by Searchlight Cyber researchers and reported to ServiceNow in early April 2026. The … More → The post ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) appeared first on Help Net Security.

Impact

ServiceNow AI Platform

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Disclosed on April 2026

Remediation

Organizations should apply any available patches from ServiceNow and review their security configurations to limit unauthorized access. Additionally, implementing monitoring for unusual activity on ServiceNow instances may help detect potential exploitation attempts.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, RCE, and 1 more.

Related Coverage

Nobody was checking the drives that encrypt your laptop

Help Net Security

A recent investigation by Milan Brož and his colleagues found that many solid-state drives (SSDs) labeled as having hardware encryption may not be secure. They tested 38 drives compliant with the TCG Opal2 standard, commonly used in millions of laptops and workstations. The researchers discovered that the drives failed to adequately protect data, raising concerns about the reliability of hardware encryption. This affects users and organizations relying on these drives for data security, as they may be under the false impression that their sensitive information is safe. With the increasing use of SSDs in computing, this issue highlights a significant gap in security practices and the need for more rigorous checks on encryption technologies.

Jul 21, 2026

AI agents are still logging in as humans

Help Net Security

Recent analysis shows that many large organizations are using multiple AI platforms simultaneously, which raises potential security concerns. Developers and marketing teams often mix sanctioned tools with personal accounts, leading to a complex environment where AI agents may log in as human users. This situation increases the risk of unauthorized access and data breaches, as the boundaries between professional and personal use of AI tools blur. The data, gathered from over 20,000 organizations, indicates that this trend has been growing since June 2022. Companies need to be aware of these risks and implement stricter security measures to protect sensitive information.

Jul 21, 2026

AI-generated reports push GNOME to shorten its disclosure window

Help Net Security

The GNOME project is responding to a surge in AI-generated security vulnerability reports that are being submitted to its maintainers. Many of these reports do not disclose that they were created using language models, leading to an overwhelming volume of submissions. As a result, GNOME is changing its policies regarding how it tracks and discloses vulnerabilities. Michael Catanzaro, who has been overseeing GNOME's security issue tracking since late 2020, is at the forefront of these changes. This shift is significant because it aims to improve the efficiency of handling security issues in open source projects, ensuring that genuine vulnerabilities are prioritized amidst the noise created by automated reports.

Jul 21, 2026

Estée Lauder discloses data breach via Oracle E-Business flaw

BleepingComputer

Estée Lauder has informed customers about a data breach that occurred due to a vulnerability in Oracle's E-Business Suite, which the company uses for its human resources operations. Hackers exploited this flaw, potentially compromising the personal data of affected individuals. While the specific details about the type of data accessed have not been disclosed, this incident raises concerns about the security of sensitive information within large organizations. Customers are advised to monitor their accounts for any unusual activity as the company works to address the breach. This incident serves as a reminder for businesses to ensure their software systems are regularly updated and secure against known vulnerabilities.

Jul 20, 2026

JadePuffer agentic attacks now target AI model data with ransomware

BleepingComputer

A new strain of malware, named EncForge, has been developed by the JadePuffer autonomous AI agent. This malware specifically targets AI-related assets, including training datasets, vector databases, and model checkpoints, by encrypting them and holding them for ransom. This shift in focus to AI model data represents a concerning trend, as organizations increasingly rely on these assets for their operations. If attackers succeed, they can disrupt AI development and implementation, potentially causing significant financial and operational damage to affected companies. As AI technology continues to evolve, the need for robust security measures to protect these critical assets becomes ever more urgent.

Jul 20, 2026

Hugging Face uses GLM 5.2 to investigate AI agent-driven cyberattack

SCM feed for Latest

Hugging Face, a company known for its work in AI and machine learning, has recently turned to an open-weight model named GLM 5.2 to investigate a cyberattack driven by AI agents. The shift to this model comes after they encountered limitations with their previous frontier model guardrails, which restricted their capabilities. This situation illustrates the evolving challenges in cybersecurity, particularly as AI technologies become more integrated into both offensive and defensive strategies. The use of AI in cyberattacks raises significant concerns about the potential for more sophisticated and automated threats. Companies in the tech sector should take note of these developments as they may need to adjust their security measures to counteract AI-driven vulnerabilities.

Jul 20, 2026