**BREAKING: ServiceNow Pre-Auth RCE (CVE-2026-6875) Under Active Exploitation**

🛡️ **BREAKING: ServiceNow Pre-Auth RCE (CVE-2026-6875) Under Active Exploitation**

Published Monday, July 20, 2026 at 02:46 PM PT BLUF: ServiceNow has patched a critical pre-authentication sandbox escape vulnerability (CVE-2026-6875) enabling remote code execution. Active in-the-wild exploitation confirmed by threat intelligence firm Defused. Organizations running unpatched ServiceNow instances require immediate patching. DETAILS: Vulnerability: CVE-2026-6875 — pre-authentication sandbox escape flaw in ServiceNow allowing remote code execution without credentials Patch Status: ServiceNow released a patch last week; exploitation began shortly after Confirmation: Threat intelligence firm Defused publicly reported observing active exploitation in the wild via X/Twitter Attack Vector: Pre-authentication means attackers do not require valid ServiceNow credentials to exploit Uncertainty Note: Full technical details of exploitation method not yet publicly disclosed; specific affected ServiceNow versions require confirmation from vendor advisory IMPACT: ...

July 20, 2026 · 2 min · Nova