Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ivanti Neurons for ITSM Vulnerabilities Resolved

Ivanti Neurons for ITSM Vulnerabilities Resolved

Posted on April 15, 2026 By CWS

Ivanti has recently released an update for its Neurons for ITSM platform, addressing two medium-severity vulnerabilities that impact both on-premises and cloud versions. These vulnerabilities, identified as CVE-2026-4913 and CVE-2026-4914, have been patched to enhance security and protect user data.

Details of the Vulnerabilities

The first vulnerability, CVE-2026-4913, carries a CVSS score of 5.7 and involves improper protection of an alternate path. This flaw could potentially allow a remote attacker, who is authenticated, to maintain access even if their account has been disabled. The second issue, CVE-2026-4914, is a stored cross-site scripting (XSS) vulnerability with a CVSS score of 5.4. It can be exploited remotely to gain limited access to information from other user sessions, though it requires user interaction and authentication to be successfully exploited.

Resolution and User Advisory

Both vulnerabilities have been addressed in the latest version, 2025.4, of Ivanti Neurons for ITSM. Users are strongly recommended to update to this version to safeguard their systems. Ivanti assures users of the cloud-based solution that the necessary fixes were automatically applied to all cloud environments as of December 12, 2025. Importantly, the company notes that there have been no reports of these vulnerabilities being exploited in real-world scenarios, and no other Ivanti products are affected by these issues.

Additional Security Updates

In addition to addressing these vulnerabilities, Ivanti has updated its advisory on two OpenSSH-related vulnerabilities, CVE-2025-26465 and CVE-2025-26466, which were disclosed earlier in the year. While Ivanti’s EPMM, Sentry, and Connector products remain unaffected by these flaws, an updated version of OpenSSH will be included in subsequent software releases to ensure continued security.

These updates underscore the importance of regular software maintenance and timely patch application to protect against emerging threats. Ivanti’s proactive measures in addressing these vulnerabilities highlight its commitment to maintaining robust security standards across its platforms.

Security Week News Tags:cloud security, cross-site scripting, CVE-2026-4913, CVE-2026-4914, Cybersecurity, IT security, Ivanti, Neurons for ITSM, on-premises, OpenSSH, security patch, software update, Vulnerability, XSS

Post navigation

Previous Post: Critical Adobe Acrobat Flaws Allow Code Execution
Next Post: MuddyWater-Style Cyber Attack Targets Middle Eastern Sectors

Related Posts

Scattered Spider Activity Drops Following Arrests, but Others Adopting Group’s Tactics Scattered Spider Activity Drops Following Arrests, but Others Adopting Group’s Tactics Security Week News
Cybersecurity M&A Roundup: 40 Deals Announced in September 2025 Cybersecurity M&A Roundup: 40 Deals Announced in September 2025 Security Week News
Atlassian Patches Critical Apache Tika Flaw Atlassian Patches Critical Apache Tika Flaw Security Week News
Adobe Patches Critical Apache Tika Bug in ColdFusion Adobe Patches Critical Apache Tika Bug in ColdFusion Security Week News
API Security Firm Wallarm Raises  Million API Security Firm Wallarm Raises $55 Million Security Week News
Motors Theme Vulnerability Exploited to Hack WordPress Websites Motors Theme Vulnerability Exploited to Hack WordPress Websites Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical GitLab Security Updates Address Key Vulnerabilities
  • Critical Flowise Vulnerability Exploit Code Released
  • Russian Spies Intensify Efforts to Acquire Western Tech
  • Introducing Pentest Swarm AI: Revolutionizing Autonomous Penetration Testing
  • Exploitation of PAN-OS Security Flaw Intensifies

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical GitLab Security Updates Address Key Vulnerabilities
  • Critical Flowise Vulnerability Exploit Code Released
  • Russian Spies Intensify Efforts to Acquire Western Tech
  • Introducing Pentest Swarm AI: Revolutionizing Autonomous Penetration Testing
  • Exploitation of PAN-OS Security Flaw Intensifies

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark