← Back

Wire · founder news, decoded · technology

Hackers are Actively Exploiting ServiceNow Vulnerability in the wild

Published

22 July 2026

Topic

technology

Sectors

CybersecurityEnterprise Software

Source

Read at cybersecuritynews.com

Verified

Fusion42 · 22 July 2026 · Fusion42 review

A critical pre-authentication sandbox escape vulnerability (CVE-2026-6875) in ServiceNow's AI Platform is being actively exploited in the wild to execute arbitrary code. Attackers can bypass authentication via the `/assessment_thanks.do` endpoint to create admin accounts, read sensitive data, and trigger commands through configured infrastructure.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

The Wire takeaway

ServiceNow customers: this exploit doesn't need your password. Patch immediately and hunt your logs for `/assessment_thanks.do` requests—attackers are already inside instances, creating admin accounts and reading your data.

Related on Wire

Topics

Cybersecurity · Enterprise Software · servicenow-rce · sandbox-escape · pre-auth-exploit · active-wild · patch-urgent