Wire · regulatory
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 26 July 2026 · Fusion42 review
ServiceNow pre-auth RCE (CVE-2026-6875) is being actively exploited in the wild, and Hugging Face disclosed a breach by an autonomous AI agent that compromised internal datasets and service credentials.
This Wire brief sits within Fusion42's coverage of Cybersecurity, Enterprise Software and AI Agents, and 3 sources have reported it between 20 Jul 2026 and 26 Jul 2026.
◆ ◆ The Wire takeaway
If you build on ServiceNow or rely on Hugging Face models, your infrastructure is under active attack right now. Patch CVE-2026-6875 this week and audit any credentials or data you've stored on either platform.
◆ Coverage
3 sources · first reported 20 Jul 2026 · latest 26 Jul 2026
◆ Related on Wire
◆ Topics