ServiceNow applied an emergency patch on June 5, 2026. An unauthenticated flaw was letting attackers query data directly from customer instances with no credentials required.
It was already being exploited before the fix landed.
ServiceNow sits at the centre of how enterprises run. ITSM. HR workflows. Security operations. Backend automation. The data stored inside those instances includes service accounts, API tokens, workflow configs, and sensitive records. Unauthorised access to that is not a contained problem.
Attackers do not need to pivot through the flaw itself. The data exposed inside the instance gives them everything they need to move next.
This is the part most teams miss about SaaS security. The platform is not your perimeter. Every integration you built, every service account you connected, every token you stored is now part of the attack surface you are defending.