Ivanti warns of critical Neurons for ITSM auth bypass flaw
ID: 3821f1e2-68fc-583a-a076-8948e94fe5e9
STIX ID: report--3821f1e2-68fc-583a-a076-8948e94fe5e9
Feed Name: Bleeping Computer
Ivanti issued May 2025 security updates to address a critical authentication bypass (CVE-2025-22462) in on-prem Neurons for ITSM and a default-credential/local privilege escalation (CVE-2025-22460) in the Cloud Services Appliance; while there is no evidence these specific CVEs are being exploited in the wild, Ivanti cautions admins to apply patches or mitigations (and to reinstall or follow special steps for CSA) because multiple other Ivanti vulnerabilities have been actively exploited by threat actors such as UNC5221.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
