ServiceNow has issued a security advisory after attackers exploit a vulnerability to gain unauthorized access to certain hosted customer instances. In its disclosure, ServiceNow says unknown threat actors take advantage of a security issue related to unauthenticated access. The company reports that, after the issue is exploited, the attackers can reach deeper access within susceptible customer environments.
According to reporting based on ServiceNow’s advisory, the exploitation involves a vulnerable application programming interface (API) endpoint. Through this pathway, an attacker without authentication can query data from customer instances, potentially exposing customer information depending on what data is accessible in the affected environments.
ServiceNow states it applies a security update to hosted customer instances on June 5, 2026, as part of its response to the vulnerability. The advisory requires customer access to view additional details, including impact specifics and recommended remediation steps. ServiceNow does not attribute the activity to a specific group in the available excerpts.