Published Monday, July 20, 2026 at 02:46 PM PT

<strong>BREAKING: ServiceNow Pre-Auth RCE (CVE-2026-6875) Under Active Exploitation</strong>

BLUF: ServiceNow has patched a critical pre-authentication sandbox escape vulnerability (CVE-2026-6875) enabling remote code execution. Active in-the-wild exploitation confirmed by threat intelligence firm Defused. Organizations running unpatched ServiceNow instances require immediate patching.


DETAILS:

  • Vulnerability: CVE-2026-6875 — pre-authentication sandbox escape flaw in ServiceNow allowing remote code execution without credentials
  • Patch Status: ServiceNow released a patch last week; exploitation began shortly after
  • Confirmation: Threat intelligence firm Defused publicly reported observing active exploitation in the wild via X/Twitter
  • Attack Vector: Pre-authentication means attackers do not require valid ServiceNow credentials to exploit
  • Uncertainty Note: Full technical details of exploitation method not yet publicly disclosed; specific affected ServiceNow versions require confirmation from vendor advisory

IMPACT:

  • Scope: Any organization running unpatched ServiceNow instances is potentially vulnerable
  • Risk Level: Critical — unauthenticated remote code execution allows complete system compromise
  • Affected Systems: ServiceNow platform deployments (ITSM, HRSD, CSM, and other modules)
  • Attack Surface: Internet-facing ServiceNow instances at highest immediate risk

RECOMMENDED ACTIONS:

  1. Immediate: Verify ServiceNow patch status across all instances; prioritize internet-facing deployments
  2. Within 24 hours: Apply ServiceNow’s security patch to all affected systems
  3. Concurrent: Monitor ServiceNow instances for suspicious pre-authentication activity; review access logs for anomalies
  4. Escalate: Alert security operations and infrastructure teams; coordinate patching windows if required
  5. Monitor: Track CISA advisories and ServiceNow security bulletins for additional guidance

SOURCES:

  • CSO Online (citing Defused threat intelligence)
  • Help Net Security