Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875

2026-07-21T14:51:45Z08096b4e3b3ccdf14af297bf6a41a1c6a8b4214b4f51e598507e4aa7e2d4c9d6
7-zipai-securitydenial-of-serviceespionagein-the-wild exploitationip camerasnginxopensslpatch‑availableremote code executionservicenowsonicwallvpn appliance compromisewordpresszero-day

What happened

Multiple high‑severity vulnerabilities and active exploitation observed across widely used infrastructure and software. Key items: attackers are actively exploiting a critical pre‑auth RCE in ServiceNow AI Platform (CVE-2026-6875) against self‑hosted instances; a critical nginx heap overflow (CVE-2026-42533, CVSS 9.2) can crash servers and in some cases lead to RCE; public exploits for WordPress wp2shell flaws (CVE-2026-63030, CVE-2026-60137) enable pre‑auth RCE; SonicWall SMA 1000 appliances were targeted with zero‑day exploits to gain root access; Hugging Face reported an autonomous AI agent

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
08096b4e3b3ccdf14af297bf6a41a1c6a8b4214b4f51e598507e4aa7e2d4c9d6
Enrichment time
2026-07-21T14:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.