Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ivanti Releases Vital Security Updates for Key Products

Ivanti Releases Vital Security Updates for Key Products

Posted on September 9, 2026 By CWS

Ivanti has recently rolled out essential security updates aimed at rectifying critical and high-severity vulnerabilities within its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) platforms. These updates, announced on Tuesday, are crucial for maintaining the security integrity of these widely-used enterprise security products.

Significant Vulnerabilities in Neurons for ITSM

The Neurons for ITSM platform has undergone significant patching, addressing eight security flaws. Of these, six are deemed critical, with potential to enable remote code execution. Notable vulnerabilities include CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646, each with a CVSS score of 9.9, indicating missing authorization issues. Additional critical flaws are CVE-2026-12650, CVE-2026-12744, and CVE-2026-12745, all with high CVSS scores due to deserialization of untrusted data.

The remaining two vulnerabilities, CVE-2026-12651 and CVE-2026-12648, while classified as high-severity, also involve the deserialization of untrusted data, posing risks of remote code execution. Notably, CVE-2026-12744 and CVE-2026-12745 can be exploited without authentication, increasing their threat potential.

Updates for Sentry and EPMM Products

In addition to Neurons for ITSM, Ivanti has provided updates for its Sentry and EPMM products. Sentry versions R10.8.2, R10.7.3, and R10.6.4 address CVE-2026-83527, a high-severity vulnerability that allows remote attackers to bypass authentication and gain administrative access without credentials.

EPMM has also been updated to versions 12.10.0.0, 12.9.0.2, and 12.8.0.4, resolving CVE-2026-18851. This high-severity flaw requires authentication for exploitation, differing from the Sentry vulnerability.

According to Ivanti, there have been no reports of these vulnerabilities being exploited in real-world scenarios, and no other Ivanti products are affected at this time.

Importance of Immediate Updates

Ivanti advises all users of the on-premises version of Neurons for ITSM to upgrade to a patched version to mitigate these vulnerabilities. The addressed flaws are included in the September 2026 security updates for versions 2025.2, 2025.3, 2025.4, and 2026.1, with further updates planned for version 2026.2, set for release on September 21.

In related news, Citrix has announced patches for medium-severity vulnerabilities in its Workspace app for Windows, highlighting the ongoing need for vigilance in software security. Other notable updates include Microsoft’s record 974 vulnerability patches and Adobe’s extensive vulnerability fixes.

As cybersecurity threats continue to evolve, timely implementation of security patches remains imperative to safeguarding enterprise systems against potential exploits.

Security Week News Tags:authentication bypass, CVE, Endpoint Manager Mobile, enterprise security, Ivanti, Neurons for ITSM, remote code execution, security updates, Sentry, Vulnerabilities

Post navigation

Previous Post: Critical cPanel Vulnerability Allows Root Access
Next Post: Windows Defender Vulnerability: New Flaw Discovered

Related Posts

Bipartisan Bill Aims to Block Chinese AI From Federal Agencies Bipartisan Bill Aims to Block Chinese AI From Federal Agencies Security Week News
F5 Addresses Critical NGINX and BIG-IP Security Flaws F5 Addresses Critical NGINX and BIG-IP Security Flaws Security Week News
480,000 Catholic Health Patients Impacted by Serviceaide Data Leak 480,000 Catholic Health Patients Impacted by Serviceaide Data Leak Security Week News
Cybersecurity Firms React to China’s Reported Software Ban Cybersecurity Firms React to China’s Reported Software Ban Security Week News
Ivanti Releases Vital Security Updates for Key Products White House to Discuss AI Advancements with Anthropic CEO Security Week News
Microsoft Addresses 622 Vulnerabilities, Highlights Two Zero-Days Microsoft Addresses 622 Vulnerabilities, Highlights Two Zero-Days Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Windows BitLocker Flaw Allows Remote Code Execution
  • Critical ICS Vulnerabilities Patched by Schneider and Siemens
  • F5 BIG-IP APM Malware Hides PHP Web Shell in Memory
  • Windows Defender Vulnerability: New Flaw Discovered
  • Ivanti Releases Vital Security Updates for Key Products

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Windows BitLocker Flaw Allows Remote Code Execution
  • Critical ICS Vulnerabilities Patched by Schneider and Siemens
  • F5 BIG-IP APM Malware Hides PHP Web Shell in Memory
  • Windows Defender Vulnerability: New Flaw Discovered
  • Ivanti Releases Vital Security Updates for Key Products

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark