Wire · regulatory
Attackers Exploit ServiceNow CVE-2026-6875 via Multiple Sandbox-Escape Routes
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 20 July 2026 · Fusion42 review
Attackers are exploiting CVE-2026-6875, a critical pre-authentication code-execution flaw in ServiceNow's AI Platform, via multiple sandbox-escape routes. Defused threat intelligence confirms active exploitation using a different gadget chain than the published proof-of-concept, meaning organisations relying on signature-based defences rather than patching remain vulnerable.
This Wire brief sits within Fusion42's coverage of Enterprise Software and Cybersecurity, and 3 sources have reported it between 20 Jul 2026 and 26 Jul 2026.
◆ ◆ The Wire takeaway
If you've built anything on top of ServiceNow's AI Platform—workflow automation, custom apps, integrations—you're under active attack right now from unauthenticated actors, and a WAF rule won't stop them. Patching is not optional this week.
◆ Coverage
3 sources · first reported 20 Jul 2026 · latest 26 Jul 2026
◆ Related on Wire
◆ Topics