Ivanti Neurons ITSM Vulnerabilities Could Allow Session Persistence
ID: 484c881f-361c-5cb5-91b2-12f54f90d03a
STIX ID: report--484c881f-361c-5cb5-91b2-12f54f90d03a
Feed Name: The Cyber Express
Ivanti disclosed two medium-severity vulnerabilities in Neurons for ITSM (CVE-2026-4913 and CVE-2026-4914) that affect version 2025.3 and earlier: CVE-2026-4913 can allow authenticated users to retain access after account deactivation, and CVE-2026-4914 is a stored XSS that may expose limited session data; Ivanti auto-patched cloud environments on December 12, 2025 and recommends on-premises customers update to 2025.4, and there is no evidence of active exploitation at disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
