ServiceNow experienced a security incident in June 2026 involving an unauthenticated access vulnerability in its API that exposed customer data. The incident allowed unauthorized access to sensitive information due to insufficient authentication controls on the affected API endpoints. The company has since addressed the vulnerability as part of its security response measures.