logo

Ivanti warns of critical Neurons for ITSM auth bypass flaw

ID: 3821f1e2-68fc-583a-a076-8948e94fe5e9

STIX ID: report--3821f1e2-68fc-583a-a076-8948e94fe5e9

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-05-13

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Ivanti issued May 2025 security updates to address a critical authentication bypass (CVE-2025-22462) in on-prem Neurons for ITSM and a default-credential/local privilege escalation (CVE-2025-22460) in the Cloud Services Appliance; while there is no evidence these specific CVEs are being exploited in the wild, Ivanti cautions admins to apply patches or mitigations (and to reinstall or follow special steps for CSA) because multiple other Ivanti vulnerabilities have been actively exploited by threat actors such as UNC5221.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.