ServiceNow Bug Exposed Enterprise Customer Data to Unauthenticated Internet Access
ServiceNow says a platform bug let unauthenticated internet users access more than intended on customer instances running its Australia releases, and it patched affected instances on June 5, 2026. The company blamed bug bounty researchers (no data used or retained) and shared IP 51.159.98.241 as an indicator to check logs.