← Back

Wire · technology

Hackers are Actively Exploiting ServiceNow Vulnerability in the wild

Published

22 July 2026

Topic

technology

Sectors

CybersecurityEnterprise Software

Source

Read at cybersecuritynews.com

Verified

Fusion42 · 22 July 2026 · Fusion42 review

A critical pre-authentication sandbox escape vulnerability (CVE-2026-6875) in ServiceNow's AI Platform is being actively exploited in the wild to execute arbitrary code. Attackers can bypass authentication via the `/assessment_thanks.do` endpoint to create admin accounts, read sensitive data, and trigger commands through configured infrastructure.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software, and 3 sources have reported it between 20 Jul 2026 and 26 Jul 2026.

◆ The Wire takeaway

ServiceNow customers: this exploit doesn't need your password. Patch immediately and hunt your logs for `/assessment_thanks.do` requests—attackers are already inside instances, creating admin accounts and reading your data.

Coverage

3 sources · first reported 20 Jul 2026 · latest 26 Jul 2026

Related on Wire

Topics

CybersecurityEnterprise Softwareservicenow-rcesandbox-escapepre-auth-exploitactive-wildpatch-urgent