ServiceNow, la RCE pre-autenticazione CVE-2026-6875 è sfruttata in the wild: istanze self-hosted da mettere in sicurezza
CVE-2026-6875 è una RCE pre-autenticazione (sandbox escape) nella piattaforma AI di ServiceNow, sfruttata in the wild dal 17 luglio. Patch self-hosted disponibili da giugno, advisory pubblico il 13 luglio. Attaccanti già attivi con una gadget chain diversa dal PoC: istanze self-hosted da aggiornare con urgenza.

