ClosedMedium impactAI Refreshed

ServiceNow discloses API vulnerability exposing customer instance data

Occurred 5 Jun 2026·Detected 9 Jun 2026·
🇺🇸 ServiceNow is a US-headquartered enterprise SaaS provider; affected instances are globally distributed, with specific exposure on the Australia platform release region8 reportsEnded 29 Jun 2026
CyberEnvironmental & IndustrialCyberCasualty & Liability

ServiceNow disclosed exploitation of an unauthenticated API endpoint on its enterprise SaaS platform, applied a hosted security update on June 5, 2026, and notified affected customers via support cases. Exposure is concentrated on the Australia platform release and older releases with specific configuration changes. Public reporting indicates queried instance data may include IT support tickets, employee records, asset inventories, security incident reports, and potentially credentials or API tokens. Vendor opacity on affected customer count, access duration, and exfiltration scope continues to constrain downstream severity banding; lifecycle moved to monitoring on June 18, 2026 absent fresh corroboration.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Medium impact. MEDIUM: ServiceNow is a widely deployed enterprise SaaS platform used by large corporates likely insured across London cyber and tech E&O books, creating aggregated supply-chain exposure on first-party and third-party liability covers. Reported data categories (tickets, employee records, incident reports, possible credentials/tokens) elevate downstream incident-response and notification burden. Materiality is tempered by the absence of confirmed mass exfiltration, ransomware activity, or critical-infrastructure impact, and by vendor containment via the June 5 hosted-instance update. Vendor opacity per TechRadar and TechTimes, and a GKG-flagged reference to ~100 customers and an 8-month access window, remain unconfirmed by ServiceNow and constrain severity banding absent insurer-side notification data.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Geographic Zone Matches

3 active matches

  • TRIA Certified Areas
    Rule-basedConfidence 100%
  • Pacific Ring of Fire
    Rule-basedConfidence 100%
  • Caribbean Hurricane Zone
    Rule-basedConfidence 100%

Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.

Affected countries

🇺🇸 United States

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts