Ivanti Releases Urgent Patches for Critical Security Flaws in Enterprise Products

www.news4hackers.com-ivanti-releases-urgent-patches-for-critical-security-flaws-in-enterprise-products-ivanti-releases-urgent-patches-for-critical-security-flaws-in-enterprise-products

Ivanti disclosed security updates to resolve critical and high-severity flaws impacting its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) platforms.

Neurons for ITSM Vulnerabilities

Critical Vulnerabilities in Neurons for ITSM

The Neurons for ITSM product received eight identified issues, six of which are classified as critical with CVSS scores ranging from 9.8 to 9.9. These include flaws related to insufficient authorization controls, such as CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646, as well as deserialization vulnerabilities like CVE-2026-12650, CVE-2026-12744, and CVE-2026-12745. Two additional high-severity deserialization flaws, CVE-2026-12651 and CVE-2026-12648, also pose risks for remote code execution. Notably, CVE-2026-12744 and CVE-2026-12745 can be exploited without requiring authentication.

Patch Details for Neurons for ITSM

All vulnerabilities were resolved through the September 2026 security updates for Neurons for ITSM versions 2025.2, 2025.3, 2025.4, and 2026.1. The fixes will also be included in the upcoming version 2026.2, scheduled for release on September 21. Ivanti advised users of the on-premises Neurons for ITSM deployment to upgrade to a patched version immediately.

Sentry and EPMM Updates

Sentry Authentication Bypass Flaw

Sentry users received updates in versions R10.8.2, R10.7.3, and R10.6.4 to address CVE-2026-83527, a high-severity authentication bypass flaw. This vulnerability allows remote, unauthenticated attackers to attain administrative privileges.

EPMM Authentication Bypass Issue

EPMM versions 12.10.0.0, 12.9.0.2, and 12.8.0.4 were released to resolve CVE-2026-18851, another authentication bypass issue. Unlike the Sentry flaw, this one requires valid credentials for exploitation.

Citrix Patches

Citrix released patches for two medium-severity flaws in its Workspace app for Windows. These include an out-of-bounds read vulnerability requiring local access and an out-of-bounds write flaw that necessitates physical access to a targeted system.

Security Implications and Recommendations

Ivanti confirmed no evidence of these vulnerabilities being actively exploited in real-world attacks. The company also stated that no other products in its portfolio are affected by these issues. Ivanti’s updates underscore the ongoing need for organizations to apply security patches promptly, particularly for tools handling sensitive infrastructure and endpoint management. The company’s advisory highlights the potential for severe consequences if these vulnerabilities remain unpatched, including unauthorized system control and data exposure.

Ivanti confirmed no evidence of these vulnerabilities being actively exploited in real-world attacks. The company also stated that no other products in its portfolio are affected by these issues.



About Author

en_USEnglish