Wire · founder news, decoded · regulatory
Attackers Exploit ServiceNow CVE-2026-6875 via Multiple Sandbox-Escape Routes
◆ Published
20 July 2026
◆ Topic
regulatory
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 20 July 2026 · Fusion42 review
Attackers are exploiting CVE-2026-6875, a critical pre-authentication code-execution flaw in ServiceNow's AI Platform, via multiple sandbox-escape routes. Defused threat intelligence confirms active exploitation using a different gadget chain than the published proof-of-concept, meaning organisations relying on signature-based defences rather than patching remain vulnerable.
This Wire brief sits within Fusion42's coverage of Enterprise Software and Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
If you've built anything on top of ServiceNow's AI Platform—workflow automation, custom apps, integrations—you're under active attack right now from unauthenticated actors, and a WAF rule won't stop them. Patching is not optional this week.
◆ Related on Wire
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution21 July 2026
- Critical ServiceNow AI flaw exploited days after patch release | news | SC Media20 July 2026
- Critical ServiceNow code execution flaw now exploited in attacks20 July 2026
- Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)9 July 2026
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC21 July 2026
- 15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code ...20 July 2026
◆ Topics
Enterprise Software · Cybersecurity · cve-2026-6875 · zero-auth-exploit · sandbox-escape · servicenow · urgent-patch