ServiceNow confirmed CVE-2026-21411, a critical MID Server auth bypass, exploited by UNC3886 to exfiltrate data from 341 customers. Patch now.

Continue reading
ServiceNow confirmed on 9 June 2026 that a critical authentication bypass in its Now Platform MID Server has been under active exploitation since at least mid-May 2026.
The attack provided unauthenticated remote actors with query-level access to customer instances; 341 tenants across finance, healthcare, and government had their records pulled, the company stated in a security advisory.
Critical Auth Bypass
The flaw, assigned CVE-2026-21411 with a CVSS 9.8, resides in the MID Server’s ECC queue endpoint. An attacker can craft a request that skips authentication checks and executes arbitrary database queries, according to an Assetnote analysis. ServiceNow patched the issue on 7 June in Utah Patch 8 and Vancouver Patch 2, and later backported fixes to older releases.
Attack Surface
Every instance where the MID Server was reachable without additional IP allow-listing or mutual TLS was exploitable. The MID Server is a Java application that proxies traffic between a ServiceNow instance and internal networks; it is used for discovery, orchestration and integrations. An exposed server effectively hands an attacker a direct query interface to the backend database.
Data Exfiltrated
Tables read from impacted instances include incident, problem, change_request, sys_user, cmdb_ci and sys_attachment. The Assetnote technical write-up states that a single unauthenticated HTTP POST to `/ecc_queue.do` with a manipulated `sysparm_table` parameter was sufficient to enumerate and dump rows. In several cases, encrypted credential fields were exfiltrated alongside user records and configuration items.
UNC3886 Ties
GreyNoise telemetry first flagged exploitation attempts from a small set of IP addresses on 14 May 2026. Mandiant later tied the post-exploitation tooling and command-and-control patterns to UNC3886, a China-nexus espionage group that has previously targeted managed service providers and SaaS management platforms. The attackers deployed lightweight webshells and the SOGU malware loader on compromised MID Server hosts.
Customer Fallout
ServiceNow’s incident response team found evidence of unauthorised data access in 341 customer tenants. Impacted organisations include multiple U.S. federal agencies, three global banks and at least two large hospital chains, according to notifications filed with CISA. Some victims confirmed that the exposed tables contained API keys and integration secrets that required immediate rotation.
Patching and Alerts
CISA added CVE-2026-21411 to its catalog of known exploited vulnerabilities on 9 June, setting a federal patching deadline of 30 June. ServiceNow invalidated all MID Server authentication tokens as a precaution and released a detection script that looks for anomalous queries against the `sys_db_object` table. The vendor urged customers to apply the relevant patch, restrict MID Server network access and rotate any stored credentials.
SaaS Pivot Trend
The attack follows a pattern of intrusions against IT service management platforms. In April 2026 ServiceNow warned about misconfigured MID Server instances after an unrelated incident, and the UNC3886 group was previously observed compromising a major MSP through a similar SaaS pivot. The rapid exploitation of CVE-2026-21411 reinforces the risk that unauthenticated integration points in enterprise SaaS continue to be targeted by advanced persistent threat actors.
Administrators should immediately update to a remediated release, enforce strict IP allow-listing on all MID Server endpoints, and enable mutual TLS where possible. Audit ECC queue logs for any queries referencing `sys_db_object` or unexpected table names. Detection rules and IOCs are published on the ServiceNow Community portal. The CISA directive requires federal civilian agencies to apply the patch and report status by the mandated date.

A publicly accessible registration portal, a misconfigured Entra tenant, and no server-side authorization checks. That was enough to reach the systems controlling live World Cup streams