Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ivanti Neurons for ITSM Vulnerabilities Resolved

Ivanti Neurons for ITSM Vulnerabilities Resolved

Posted on April 15, 2026 By CWS

Ivanti has recently released an update for its Neurons for ITSM platform, addressing two medium-severity vulnerabilities that impact both on-premises and cloud versions. These vulnerabilities, identified as CVE-2026-4913 and CVE-2026-4914, have been patched to enhance security and protect user data.

Details of the Vulnerabilities

The first vulnerability, CVE-2026-4913, carries a CVSS score of 5.7 and involves improper protection of an alternate path. This flaw could potentially allow a remote attacker, who is authenticated, to maintain access even if their account has been disabled. The second issue, CVE-2026-4914, is a stored cross-site scripting (XSS) vulnerability with a CVSS score of 5.4. It can be exploited remotely to gain limited access to information from other user sessions, though it requires user interaction and authentication to be successfully exploited.

Resolution and User Advisory

Both vulnerabilities have been addressed in the latest version, 2025.4, of Ivanti Neurons for ITSM. Users are strongly recommended to update to this version to safeguard their systems. Ivanti assures users of the cloud-based solution that the necessary fixes were automatically applied to all cloud environments as of December 12, 2025. Importantly, the company notes that there have been no reports of these vulnerabilities being exploited in real-world scenarios, and no other Ivanti products are affected by these issues.

Additional Security Updates

In addition to addressing these vulnerabilities, Ivanti has updated its advisory on two OpenSSH-related vulnerabilities, CVE-2025-26465 and CVE-2025-26466, which were disclosed earlier in the year. While Ivanti’s EPMM, Sentry, and Connector products remain unaffected by these flaws, an updated version of OpenSSH will be included in subsequent software releases to ensure continued security.

These updates underscore the importance of regular software maintenance and timely patch application to protect against emerging threats. Ivanti’s proactive measures in addressing these vulnerabilities highlight its commitment to maintaining robust security standards across its platforms.

Security Week News Tags:cloud security, cross-site scripting, CVE-2026-4913, CVE-2026-4914, Cybersecurity, IT security, Ivanti, Neurons for ITSM, on-premises, OpenSSH, security patch, software update, Vulnerability, XSS

Post navigation

Previous Post: Critical Adobe Acrobat Flaws Allow Code Execution
Next Post: MuddyWater-Style Cyber Attack Targets Middle Eastern Sectors

Related Posts

Android Malware Uses AI for Extended Device Control Android Malware Uses AI for Extended Device Control Security Week News
Tech Giants Unite to Tackle Online Scams and Fraud Tech Giants Unite to Tackle Online Scams and Fraud Security Week News
Former Accenture Employee Charged Over Cybersecurity Fraud Former Accenture Employee Charged Over Cybersecurity Fraud Security Week News
Malicious Chrome Extensions Compromise User Data Malicious Chrome Extensions Compromise User Data Security Week News
Critical Security Flaw in BeyondTrust Products Patched Critical Security Flaw in BeyondTrust Products Patched Security Week News
Iranian Cyber Group Targets US Organizations Amid Tensions Iranian Cyber Group Targets US Organizations Amid Tensions Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Struggle with TP-Link Router Vulnerability
  • Vercel Data Breach Linked to Context AI Compromise
  • Flowise Vulnerability Exposes Millions to Remote Code Risks
  • Vercel Data Breach: Security Measures and Investigation
  • OpenAI Launches Expanded Cyber Defense with GPT-5.4-Cyber

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Struggle with TP-Link Router Vulnerability
  • Vercel Data Breach Linked to Context AI Compromise
  • Flowise Vulnerability Exposes Millions to Remote Code Risks
  • Vercel Data Breach: Security Measures and Investigation
  • OpenAI Launches Expanded Cyber Defense with GPT-5.4-Cyber

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark