logo

Ivanti Neurons for ITSM Vulnerabilities Let Remote Attackers Obtain User Sessions

ID: e325f12f-60ca-5805-8c4b-ac8f62f6b894

STIX ID: report--e325f12f-60ca-5805-8c4b-ac8f62f6b894

Feed Name: Cyber Press

Threat Score
50/100

Date Published: 2026-04-15

Date Updated: 2026-04-15

Author: AnuPriya

...
...

Ivanti released an advisory for two medium-severity vulnerabilities in Ivanti Neurons for ITSM (CVE-2026-4913 — improper protection of an alternate path allowing persistent "zombie" access after account disablement; CVE-2026-4914 — stored XSS enabling capture of data from other sessions). Cloud instances were patched automatically to version 2025.4, while on-premise installations must be manually updated via the Ivanti License System; no active exploitation has been observed but organizations are urged to patch promptly due to the central role of ITSM platforms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.