Wire · founder news, decoded · technology
Hackers are Actively Exploiting ServiceNow Vulnerability in the wild
◆ Published
22 July 2026
◆ Topic
technology
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 22 July 2026 · Fusion42 review
A critical pre-authentication sandbox escape vulnerability (CVE-2026-6875) in ServiceNow's AI Platform is being actively exploited in the wild to execute arbitrary code. Attackers can bypass authentication via the `/assessment_thanks.do` endpoint to create admin accounts, read sensitive data, and trigger commands through configured infrastructure.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
ServiceNow customers: this exploit doesn't need your password. Patch immediately and hunt your logs for `/assessment_thanks.do` requests—attackers are already inside instances, creating admin accounts and reading your data.
◆ Related on Wire
- Attackers Exploit ServiceNow CVE-2026-6875 via Multiple Sandbox-Escape Routes20 July 2026
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution21 July 2026
- Critical ServiceNow AI flaw exploited days after patch release | news | SC Media20 July 2026
- Critical ServiceNow code execution flaw now exploited in attacks20 July 2026
- CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild23 July 2026
- Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)9 July 2026
◆ Topics
Cybersecurity · Enterprise Software · servicenow-rce · sandbox-escape · pre-auth-exploit · active-wild · patch-urgent