Atacantes explotan fallo crítico de ServiceNow RCE CVE-2026-6875
Resumen
Los atacantes están explotando una vulnerabilidad crítica en la plataforma ServiceNow AI, permitiendo la ejecución remota de código sin autenticación en instancias autoalojadas. La vulnerabilidad, identificada como CVE-2026-6875, fue divulgada por investigadores de Searchlight Cyber el 14 de julio, y ServiceNow lanzó parches para instancias autoalojadas el mismo día. Desde el 17 de julio, los atacantes han comenzado a explotar esta vulnerabilidad
Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical pre-authentication remote code execution vulnerability, tracked as CVE-2026-6875, in the ServiceNow AI Platform on July 14. The same day, ServiceNow released patches for self-hosted instances. Since July 17, attackers have started exploiting it in […]