Wire · technology
Hackers are Actively Exploiting ServiceNow Vulnerability in the wild
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 22 July 2026 · Fusion42 review
A critical pre-authentication sandbox escape vulnerability (CVE-2026-6875) in ServiceNow's AI Platform is being actively exploited in the wild to execute arbitrary code. Attackers can bypass authentication via the `/assessment_thanks.do` endpoint to create admin accounts, read sensitive data, and trigger commands through configured infrastructure.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software, and 3 sources have reported it between 20 Jul 2026 and 26 Jul 2026.
◆ ◆ The Wire takeaway
ServiceNow customers: this exploit doesn't need your password. Patch immediately and hunt your logs for `/assessment_thanks.do` requests—attackers are already inside instances, creating admin accounts and reading your data.
◆ Coverage
3 sources · first reported 20 Jul 2026 · latest 26 Jul 2026
◆ Related on Wire
◆ Topics