Ivanti Neurons for ITSM Vulnerabilities Allow Remote Attacker to Obtain User Sessions
ID: c68f658a-3298-5137-8e92-af4af6fc9424
STIX ID: report--c68f658a-3298-5137-8e92-af4af6fc9424
Feed Name: cybersecurityNews.com
Ivanti issued updates for two medium-severity vulnerabilities in Ivanti Neurons for ITSM (CVE-2026-4913 and CVE-2026-4914). CVE-2026-4913 permits a remote authenticated attacker to retain access even after account disablement, while CVE-2026-4914 is a stored XSS that can exfiltrate limited session data; both require user interaction and affect versions before 2025.4. Ivanti patched the issues in version 2025.4 (cloud environments already updated on Dec 12, 2025) and reports no evidence of active exploitation, advising on-premise customers to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
