Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
2026-07-21T14:51:45Z•08096b4e3b3ccdf14af297bf6a41a1c6a8b4214b4f51e598507e4aa7e2d4c9d6
7-zipai-securitydenial-of-serviceespionagein-the-wild exploitationip camerasnginxopensslpatch‑availableremote code executionservicenowsonicwallvpn appliance compromisewordpresszero-day
What happened
Multiple high‑severity vulnerabilities and active exploitation observed across widely used infrastructure and software. Key items: attackers are actively exploiting a critical pre‑auth RCE in ServiceNow AI Platform (CVE-2026-6875) against self‑hosted instances; a critical nginx heap overflow (CVE-2026-42533, CVSS 9.2) can crash servers and in some cases lead to RCE; public exploits for WordPress wp2shell flaws (CVE-2026-63030, CVE-2026-60137) enable pre‑auth RCE; SonicWall SMA 1000 appliances were targeted with zero‑day exploits to gain root access; Hugging Face reported an autonomous AI agent
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 08096b4e3b3ccdf14af297bf6a41a1c6a8b4214b4f51e598507e4aa7e2d4c9d6
- Enrichment time
- 2026-07-21T14:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.