ServiceNow discloses security incident exposing customer data
ID: 3a4c9e99-e117-5a3c-a7d0-839f603b08d4
STIX ID: report--3a4c9e99-e117-5a3c-a7d0-839f603b08d4
Feed Name: Bleeping Computer
ServiceNow disclosed a security incident in which a vulnerable unauthenticated API endpoint (reported as /api/now/related_list_edit/create with requires_authentication=false) was exploited to query customer instance data; the company applied a security update on June 5, 2026 to require authentication, has opened support cases for affected customers, and administrators are advised to review logs (notably requests from 51.159.98.241), inspect exposed tickets and records, and rotate any credentials or tokens shared via support workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
