ServiceNow CVE-2026-6875: pre-auth sandbox escape RCE now exploited
ServiceNow's July 13 patch closes CVE-2026-6875 — a pre-auth sandbox escape in the AI Platform that yields unauthenticated RCE. Defused observed in-the-wild exploitation five days later.