Home / Jun 12, 2026 / Story
0
#8 The Hacker News general June 10, 2026 at 07:02 UTC

ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances

By [email protected] (The Hacker News)

AI Summary

ServiceNow patched a vulnerability on June 5, 2026 that allowed unauthenticated users to gain deeper unauthorized access to hosted customer instances — a flaw the company reportedly had known about since April 7. Threat actors actively exploited the vulnerability against some customers before the patch was applied, making this a confirmed zero-day exploitation window of approximately two months. Organizations using ServiceNow should audit access logs from April 7 onward for signs of unauthorized activity.

Relevance score: 78.0/100

# More from June 12