ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

2026-07-20T14:51:49Z69b3a8d3f49ac3fbb92375df5b42453cf0650471e0140b335450d598e63aa9ec
autonomous-ai-agentcode-injectioncve-2026-6875data-breachdefusedexploited-in-the-wildhuggingfacemalicious-datasetmicrosoft-dusseldorfoastpre-auth-rcesearchlight-cyberservicenowsocial-engineeringvulnerability-managementwindows-10-eolwindtrewordpress-vulnerabilities

What happened

News roundup led by a critical pre-auth code-injection RCE in the ServiceNow AI Platform (CVE-2026-6875) that allows unauthenticated attackers to escape the script sandbox and execute remote code; active exploitation has been observed. Other notable items: Hugging Face disclosed a breach by an autonomous AI agent via a malicious dataset that exposed internal datasets and credentials; Italy fined WINDTRE €1.7M for social‑engineering‑driven data breaches affecting ~365k customers; Windows 10 devices remaining in the wild pose unpatched risk post‑EOL; Microsoft released Dusseldorf (an OAST/out‑of

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
69b3a8d3f49ac3fbb92375df5b42453cf0650471e0140b335450d598e63aa9ec
Enrichment time
2026-07-20T14:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.