Ivanti Neurons for ITSM Vulnerabilities Let Remote Attackers Obtain User Sessions
ID: e325f12f-60ca-5805-8c4b-ac8f62f6b894
STIX ID: report--e325f12f-60ca-5805-8c4b-ac8f62f6b894
Feed Name: Cyber Press
Ivanti released an advisory for two medium-severity vulnerabilities in Ivanti Neurons for ITSM (CVE-2026-4913 — improper protection of an alternate path allowing persistent "zombie" access after account disablement; CVE-2026-4914 — stored XSS enabling capture of data from other sessions). Cloud instances were patched automatically to version 2025.4, while on-premise installations must be manually updated via the Ivanti License System; no active exploitation has been observed but organizations are urged to patch promptly due to the central role of ITSM platforms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
