Ivanti issued security updates for multiple enterprise products, including Ivanti Connect Secure, Policy Secure, and Ivanti Neurons for ITSM, as the company continued remediation across its remote access and IT service management portfolio. The Neurons for ITSM fixes arrived in version 2025.4 and addressed CVE-2026-4913 and CVE-2026-4914, affecting version 2025.3 and earlier in both on-premises and cloud deployments; Ivanti said cloud instances had already been patched and urged on-premises customers to upgrade through the Ivanti License System.
According to Ivanti, CVE-2026-4913 is an improper path protection flaw that could allow a remote authenticated attacker to retain access after an administrator disables the account, while CVE-2026-4914 is a stored XSS issue that could let an authenticated attacker access limited data from other users’ sessions. Ivanti said it was not aware of active exploitation and had no indicators of compromise for the Neurons flaws, while its separate advisory for Connect Secure and Policy Secure signaled additional security remediation affecting those products.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On June 1, 2026, Ivanti published a security advisory for CVE-2026-9614 affecting Ivanti Neurons for ITSM on-premises version 2025.4 and prior and cloud version 2026.1 and prior. The Canadian Centre for Cyber Security urged administrators to review Ivanti’s advisory and apply the necessary updates.
Ivanti said SaaS deployments of Ivanti Neurons for ITSM were automatically remediated through service updates on May 24 and May 25, 2026, for CVE-2026-9614. The flaw is an improper access control issue that can let an authenticated remote user escalate privileges to administrator.
Ivanti released version 2025.4 of Ivanti Neurons for ITSM to address CVE-2026-4913, an improper path protection issue, and CVE-2026-4914, a stored XSS flaw. The company said affected versions include 2025.3 and earlier, no active exploitation was known, and on-premise customers should upgrade manually.
Ivanti remediated two vulnerabilities affecting Ivanti Neurons for ITSM cloud deployments. According to the later disclosure, the cloud fixes were already applied by Ivanti on December 12, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcecyber.gc.ca
Open sourceivanti.com
Open sourcecybersecuritynews.com
Open sourcehub.ivanti.com
Open sourceforums.ivanti.com
Open sourceivanti.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.