Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ivanti Releases Vital Security Updates for Key Products

Ivanti Releases Vital Security Updates for Key Products

Posted on September 9, 2026 By CWS

Ivanti has recently rolled out essential security updates aimed at rectifying critical and high-severity vulnerabilities within its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) platforms. These updates, announced on Tuesday, are crucial for maintaining the security integrity of these widely-used enterprise security products.

Significant Vulnerabilities in Neurons for ITSM

The Neurons for ITSM platform has undergone significant patching, addressing eight security flaws. Of these, six are deemed critical, with potential to enable remote code execution. Notable vulnerabilities include CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646, each with a CVSS score of 9.9, indicating missing authorization issues. Additional critical flaws are CVE-2026-12650, CVE-2026-12744, and CVE-2026-12745, all with high CVSS scores due to deserialization of untrusted data.

The remaining two vulnerabilities, CVE-2026-12651 and CVE-2026-12648, while classified as high-severity, also involve the deserialization of untrusted data, posing risks of remote code execution. Notably, CVE-2026-12744 and CVE-2026-12745 can be exploited without authentication, increasing their threat potential.

Updates for Sentry and EPMM Products

In addition to Neurons for ITSM, Ivanti has provided updates for its Sentry and EPMM products. Sentry versions R10.8.2, R10.7.3, and R10.6.4 address CVE-2026-83527, a high-severity vulnerability that allows remote attackers to bypass authentication and gain administrative access without credentials.

EPMM has also been updated to versions 12.10.0.0, 12.9.0.2, and 12.8.0.4, resolving CVE-2026-18851. This high-severity flaw requires authentication for exploitation, differing from the Sentry vulnerability.

According to Ivanti, there have been no reports of these vulnerabilities being exploited in real-world scenarios, and no other Ivanti products are affected at this time.

Importance of Immediate Updates

Ivanti advises all users of the on-premises version of Neurons for ITSM to upgrade to a patched version to mitigate these vulnerabilities. The addressed flaws are included in the September 2026 security updates for versions 2025.2, 2025.3, 2025.4, and 2026.1, with further updates planned for version 2026.2, set for release on September 21.

In related news, Citrix has announced patches for medium-severity vulnerabilities in its Workspace app for Windows, highlighting the ongoing need for vigilance in software security. Other notable updates include Microsoft’s record 974 vulnerability patches and Adobe’s extensive vulnerability fixes.

As cybersecurity threats continue to evolve, timely implementation of security patches remains imperative to safeguarding enterprise systems against potential exploits.

Security Week News Tags:authentication bypass, CVE, Endpoint Manager Mobile, enterprise security, Ivanti, Neurons for ITSM, remote code execution, security updates, Sentry, Vulnerabilities

Post navigation

Previous Post: Critical cPanel Vulnerability Allows Root Access
Next Post: Windows Defender Vulnerability: New Flaw Discovered

Related Posts

Cisco Patches Critical Vulnerability in Firewall Management Platform Cisco Patches Critical Vulnerability in Firewall Management Platform Security Week News
StrongestLayer Secures .1M to Enhance Email Security StrongestLayer Secures $4.1M to Enhance Email Security Security Week News
Chrome Update Fixes Zero-Day Among 21 Vulnerabilities Chrome Update Fixes Zero-Day Among 21 Vulnerabilities Security Week News
Microsoft Alerts US Firms to Advanced Phishing Scheme Microsoft Alerts US Firms to Advanced Phishing Scheme Security Week News
0,000 Paid Out at Zeroday.Cloud for Open Source Software Exploits $320,000 Paid Out at Zeroday.Cloud for Open Source Software Exploits Security Week News
Citrix Patches Exploited NetScaler Zero-Day Citrix Patches Exploited NetScaler Zero-Day Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows Defender Vulnerability: New Flaw Discovered
  • Ivanti Releases Vital Security Updates for Key Products
  • Critical cPanel Vulnerability Allows Root Access
  • Chrome Users Urged to Update Amid V8 Security Flaw
  • Microsoft Resolves Record 974 Vulnerabilities in September

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows Defender Vulnerability: New Flaw Discovered
  • Ivanti Releases Vital Security Updates for Key Products
  • Critical cPanel Vulnerability Allows Root Access
  • Chrome Users Urged to Update Amid V8 Security Flaw
  • Microsoft Resolves Record 974 Vulnerabilities in September

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark