Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ivanti Neurons for ITSM Vulnerabilities Resolved

Ivanti Neurons for ITSM Vulnerabilities Resolved

Posted on April 15, 2026 By CWS

Ivanti has recently released an update for its Neurons for ITSM platform, addressing two medium-severity vulnerabilities that impact both on-premises and cloud versions. These vulnerabilities, identified as CVE-2026-4913 and CVE-2026-4914, have been patched to enhance security and protect user data.

Details of the Vulnerabilities

The first vulnerability, CVE-2026-4913, carries a CVSS score of 5.7 and involves improper protection of an alternate path. This flaw could potentially allow a remote attacker, who is authenticated, to maintain access even if their account has been disabled. The second issue, CVE-2026-4914, is a stored cross-site scripting (XSS) vulnerability with a CVSS score of 5.4. It can be exploited remotely to gain limited access to information from other user sessions, though it requires user interaction and authentication to be successfully exploited.

Resolution and User Advisory

Both vulnerabilities have been addressed in the latest version, 2025.4, of Ivanti Neurons for ITSM. Users are strongly recommended to update to this version to safeguard their systems. Ivanti assures users of the cloud-based solution that the necessary fixes were automatically applied to all cloud environments as of December 12, 2025. Importantly, the company notes that there have been no reports of these vulnerabilities being exploited in real-world scenarios, and no other Ivanti products are affected by these issues.

Additional Security Updates

In addition to addressing these vulnerabilities, Ivanti has updated its advisory on two OpenSSH-related vulnerabilities, CVE-2025-26465 and CVE-2025-26466, which were disclosed earlier in the year. While Ivanti’s EPMM, Sentry, and Connector products remain unaffected by these flaws, an updated version of OpenSSH will be included in subsequent software releases to ensure continued security.

These updates underscore the importance of regular software maintenance and timely patch application to protect against emerging threats. Ivanti’s proactive measures in addressing these vulnerabilities highlight its commitment to maintaining robust security standards across its platforms.

Security Week News Tags:cloud security, cross-site scripting, CVE-2026-4913, CVE-2026-4914, Cybersecurity, IT security, Ivanti, Neurons for ITSM, on-premises, OpenSSH, security patch, software update, Vulnerability, XSS

Post navigation

Previous Post: Critical Adobe Acrobat Flaws Allow Code Execution
Next Post: MuddyWater-Style Cyber Attack Targets Middle Eastern Sectors

Related Posts

China-Linked Hackers Hijack Web Traffic to Deliver Backdoor China-Linked Hackers Hijack Web Traffic to Deliver Backdoor Security Week News
Eclypsium Secures M for Enhanced Supply Chain Security Eclypsium Secures $25M for Enhanced Supply Chain Security Security Week News
New Campaigns Distribute Malware via Open Source Hacking Tools New Campaigns Distribute Malware via Open Source Hacking Tools Security Week News
Marlboro-Chesterfield Pathology Data Breach Impacts 235,000 People Marlboro-Chesterfield Pathology Data Breach Impacts 235,000 People Security Week News
Securing Industrial Control Systems: Challenges and Future Securing Industrial Control Systems: Challenges and Future Security Week News
Several Vulnerabilities Patched in AI Code Editor Cursor  Several Vulnerabilities Patched in AI Code Editor Cursor  Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WordPress Plugins Compromised by Hidden Malware Backdoor
  • Hackers Exploit Google Cloud to Deliver Remcos RAT
  • Trump Advocates for Extending Surveillance Program Amid Privacy Concerns
  • MuddyWater-Style Cyber Attack Targets Middle Eastern Sectors
  • Ivanti Neurons for ITSM Vulnerabilities Resolved

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WordPress Plugins Compromised by Hidden Malware Backdoor
  • Hackers Exploit Google Cloud to Deliver Remcos RAT
  • Trump Advocates for Extending Surveillance Program Amid Privacy Concerns
  • MuddyWater-Style Cyber Attack Targets Middle Eastern Sectors
  • Ivanti Neurons for ITSM Vulnerabilities Resolved

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark