logo

ServiceNow discloses security incident exposing customer data

ID: 3a4c9e99-e117-5a3c-a7d0-839f603b08d4

STIX ID: report--3a4c9e99-e117-5a3c-a7d0-839f603b08d4

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Lawrence Abrams

...
...

ServiceNow disclosed a security incident in which a vulnerable unauthenticated API endpoint (reported as /api/now/related_list_edit/create with requires_authentication=false) was exploited to query customer instance data; the company applied a security update on June 5, 2026 to require authentication, has opened support cases for affected customers, and administrators are advised to review logs (notably requests from 51.159.98.241), inspect exposed tickets and records, and rotate any credentials or tokens shared via support workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.