<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cve-2026-6875-pre-auth-rce-in-servicenow-is-being-actively-exploited-tzr9vspi5" -->

---
title: CVE-2026-6875: Pre-auth RCE in ServiceNow is being...
description: A critical pre-authentication remote code execution vulnerability (CVE-2026-6875) in ServiceNow&#x27;s AI Platform is being actively exploited in the wild....
canonical: https://daily.dev/posts/cve-2026-6875-pre-auth-rce-in-servicenow-is-being-actively-exploited-tzr9vspi5
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: CVE-2026-6875: Pre-auth RCE in ServiceNow is being actively exploited | daily.dev
og:description: A critical pre-authentication remote code execution vulnerability (CVE-2026-6875) in ServiceNow&#x27;s AI Platform is being actively exploited in the wild....
og:url: https://daily.dev/posts/cve-2026-6875-pre-auth-rce-in-servicenow-is-being-actively-exploited-tzr9vspi5
og:image: https://api.daily.dev/og/posts/tzR9VSPi5.png
og:image:alt: CVE-2026-6875: Pre-auth RCE in ServiceNow is being actively exploited
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CVE-2026-6875: Pre-auth RCE in ServiceNow is being actively exploited

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 3 upvotes · 0 comments

## Summary

A critical pre-authentication remote code execution vulnerability (CVE-2026-6875) in ServiceNow's AI Platform is being actively exploited in the wild. Discovered by Searchlight Cyber, the flaw allows unauthenticated attackers to escape ServiceNow's sandbox and execute arbitrary code. ServiceNow patched hosted instances and released self-hosted updates on July 13th, but exploitation began within days. Notably, attackers are using a different exploit route than the published proof-of-concept, making signature-based defenses less reliable. Self-hosted ServiceNow customers are urged to apply patches immediately.

## Content

A critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform is now being exploited in the wild, just days after a patch was released.

## What the vulnerability is

CVE-2026-6875 is a sandbox escape flaw discovered by Searchlight Cyber's hash_kitten. It lets unauthenticated attackers break out of the sandbox and execute code remotely — no credentials required. ServiceNow patched hosted instances and released updates for self-hosted deployments on July 13th.

Exploitation started almost immediately after.

## What attackers are doing

Threat intelligence firm Defused confirmed in-the-wild attacks over the weekend. The more concerning detail: at least one attacker isn't using the published proof-of-concept. They've adapted their technique to bypass all five mitigations ServiceNow implemented, taking a different exploit route entirely.

ServiceNow's own advisory hasn't yet flagged the vulnerability as actively exploited, though the company is urging customers to apply patches immediately.

## The bigger problem

This isn't just a patching story. Security analysts are pointing to a pattern: enterprise AI platforms are being deployed faster than threat models are updated, and the sandbox layer — the boundary that's supposed to contain AI-driven code execution — keeps failing in repeatable ways.

The practical advice from analysts: CISOs should treat core SaaS platforms as part of the internal attack surface, not as trusted external services. And before the next incident, it's worth auditing every AI-enabled vendor's sandbox architecture rather than waiting to see if it holds.

If you're running a self-hosted ServiceNow instance, patch now.

---

Tags: [#security](https://daily.dev/tags/security), [#vulnerability](https://daily.dev/tags/vulnerability)

[View this post on daily.dev](https://daily.dev/posts/cve-2026-6875-pre-auth-rce-in-servicenow-is-being-actively-exploited-tzr9vspi5)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"CVE-2026-6875: Pre-auth RCE in ServiceNow is being actively exploited","url":"https://daily.dev/posts/cve-2026-6875-pre-auth-rce-in-servicenow-is-being-actively-exploited-tzr9vspi5","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cve-2026-6875-pre-auth-rce-in-servicenow-is-being-actively-exploited-tzr9vspi5"},"datePublished":"2026-07-20T09:31:16.822Z","dateModified":"2026-07-20T20:27:54.270Z","description":"A critical pre-authentication remote code execution vulnerability (CVE-2026-6875) in ServiceNow's AI Platform is being actively exploited in the wild....","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/edc9b8b39e1ceed0ea507811548dd70b?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/edc9b8b39e1ceed0ea507811548dd70b?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cve-2026-6875-pre-auth-rce-in-servicenow-is-being-actively-exploited-tzr9vspi5","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":3},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,vulnerability","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"CVE-2026-6875: Pre-auth RCE in ServiceNow is being actively exploited"}]}
```

