Lyrie
Active Exploitation
1 sources verified·1 min read
By Lyrie Threat Intelligence·7/18/2026

0day Intel: ⚠️ We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-

Source: X search for PoC exploit 2026

Posted: 2026-07-18T09:55:34.000Z

Likes: 25

Full Tweet

⚠️ We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875)

The payloads hit the same pre-auth sink @SLCyberSec documented (/assessment_thanks.do), but the sandbox-escape gadget reaches the same code-execution primitive by a https://t.co/E0QZDmer2l

Source Link

https://x.com/i/status/2078418391321219448

Lyrie Verdict

Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces — no signature update required.

Validated sources

  1. [1]@1686989812702617600 on X