← Back

Wire · regulatory

Attackers Exploit ServiceNow CVE-2026-6875 via Multiple Sandbox-Escape Routes

Published

20 July 2026

Topic

regulatory

Sectors

Enterprise SoftwareCybersecurity

Source

Read at techtimes.com

Verified

Fusion42 · 20 July 2026 · Fusion42 review

Attackers are exploiting CVE-2026-6875, a critical pre-authentication code-execution flaw in ServiceNow's AI Platform, via multiple sandbox-escape routes. Defused threat intelligence confirms active exploitation using a different gadget chain than the published proof-of-concept, meaning organisations relying on signature-based defences rather than patching remain vulnerable.

This Wire brief sits within Fusion42's coverage of Enterprise Software and Cybersecurity, and 3 sources have reported it between 20 Jul 2026 and 26 Jul 2026.

◆ The Wire takeaway

If you've built anything on top of ServiceNow's AI Platform—workflow automation, custom apps, integrations—you're under active attack right now from unauthenticated actors, and a WAF rule won't stop them. Patching is not optional this week.

Coverage

3 sources · first reported 20 Jul 2026 · latest 26 Jul 2026

Related on Wire

Topics

Enterprise SoftwareCybersecuritycve-2026-6875zero-auth-exploitsandbox-escapeservicenowurgent-patch