A critical remote code execution vulnerability in ServiceNow (CVE-2026-6875) is reportedly being exploited in the wild just days after patches were released on July 14 and technical details were publicly disclosed. Threat intelligence firm Defused observed exploitation activity on July 18, though closer analysis revealed the payload was identical to a published proof-of-concept rather than an independently developed exploit. ServiceNow states it has found no evidence of compromise on its hosted instances, and there is speculation the activity may originate from security researchers rather than malicious threat actors.