logo

Ivanti ITSM Flaw Could Allow Attackers to Escalate to Admin Access

ID: f0ce2019-0a75-5cdb-9b43-754878906cdd

STIX ID: report--f0ce2019-0a75-5cdb-9b43-754878906cdd

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Divya

...
...

Ivanti released patches for CVE-2026-9614, an improper access control vulnerability in Ivanti Neurons for ITSM that allows low-privileged authenticated attackers to escalate to full administrative access (CVSS 8.8). The flaw affects cloud and on‑premises versions; on‑premises patches and cloud service updates have been issued and applied between May 24–25, 2026. Ivanti reports no evidence of active exploitation, but organizations are advised to apply patches, restrict ITSM access, and monitor for misuse of privileged accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.