logo

ServiceNow Discloses Security Incident Exposing Customer Data

ID: 5cae07a3-2ca2-551d-8d7d-35aae93f8a28

STIX ID: report--5cae07a3-2ca2-551d-8d7d-35aae93f8a28

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-06-10

Date Updated: 2026-06-11

Author: Deeba Ahmed

...
...

ServiceNow patched an unauthenticated API access issue (reported linked to `/api/now/related_list_edit/create`) on 5 June 2026 after observing successful queries against some customer instances; administrators reported suspicious requests potentially appearing as the Guest user and a notable IP indicator (51.159.98.241). The vendor has not confirmed exact data exfiltrated, and community posts allege earlier internal tracking and delayed prioritization, so affected customers should review logs, exposed records, rotate secrets, and verify Scripted REST resource authentication settings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.