Attackers are now actively exploiting a critical remote code execution vulnerability in ServiceNow, just three days after patches were released. Tracked as CVE-2026-6875, this pre-authentication flaw allows unauthenticated attackers to seize complete control of affected systems, putting self-hosted deployments at severe risk.

The vulnerability was disclosed on July 14, the same day ServiceNow issued patches for self-hosted versions. According to Security Affairs, active exploitation in the wild was observed by July 17, highlighting a perilously narrow window for defense.

CVE-2026-6875 carries a CVSS score of 9.8, marking it as critical. The threat is particularly severe because it requires no credentials or prior access; attackers can execute arbitrary code remotely, potentially leading to full system compromise.

The vulnerability exclusively affects self-hosted instances of ServiceNow. Organizations relying on ServiceNow's cloud-hosted services remain unaffected, as the vendor manages and secures those environments. This split places the entire burden of remediation on internal teams responsible for on-premises installations.

The rapid weaponization—exploits emerging within three days of disclosure—underscores the urgency of immediate action. Any self-hosted system exposed to the internet between July 14 and now must be assumed compromised until proven otherwise.

Security experts recommend deploying the official ServiceNow patches without delay. For systems that were vulnerable during the exploitation window, a full forensic investigation is necessary. This should include a review of system logs for indicators of compromise and an audit of administrative actions and user account activities for any signs of unauthorized access.

This incident reflects a growing cybersecurity challenge: the shrinking interval between vulnerability disclosure and exploitation. For organizations managing their own infrastructure, it reinforces the critical need for agile patch management and continuous vulnerability monitoring to mitigate such rapidly emerging threats.


攻擊者現正積極利用 ServiceNow 中的一個關鍵遠端執行代碼漏洞,而修補程式僅在三日前發佈。此漏洞編號為 CVE-2026-6875,屬於預驗證缺陷,允許未經認證的攻擊者完全控制受影響的系統,使自託管部署面臨嚴重風險。

該漏洞於 7 月 14 日被披露,同日 ServiceNow 為自託管版本發佈了修補程式。據 Security Affairs 報導,7 月 17 日已觀察到在野活躍利用,凸顯出防禦窗口期極其緊迫。

CVE-2026-6875 的 CVSS 評分高達 9.8,被列為關鍵級別。該威脅特別嚴重,因為它無需憑證或先前存取權限;攻擊者可遠端執行任意代碼,可能導致系統被完全入侵。

此漏洞僅影響 ServiceNow 的自託管實例。依賴 ServiceNow 雲端託管服務的組織不受影響,因為供應商負責管理並保護這些環境。這意味著修補責任完全落在負責本地安裝的內部團隊身上。

漏洞公開後僅三天就出現攻擊利用程式,其迅速武器化凸顯了立即行動的緊急性。任何在 7 月 14 日至今期間暴露於互聯網的自託管系統,在證實安全之前,均應被視為已遭入侵。

安全專家建議立即部署 ServiceNow 官方修補程式。對於在漏洞利用窗口期間受影響的系統,必須進行全面的數碼鑑識調查。這包括檢查系統日誌以尋找入侵指標,以及審核管理操作和用戶帳號活動,以偵測任何未經授權存取的跡象。

此事件反映了一個日益嚴峻的網絡安全挑戰:漏洞公開與遭利用之間的時間間隔不斷縮短。對於自行管理基礎設施的組織而言,這強調了敏捷修補管理和持續漏洞監控以應對此類快速湧現威脅的關鍵必要性。

新聞來源 / Original News Source