Multiples vulnérabilités dans les produits Ivanti (09 septembre 2026)
Multiple vulnerabilities have been discovered in Ivanti products, including Neurons for ITSM and Sentry. These vulnerabilities allow for remote code execution, privilege escalation, and policy bypass. Users are advised to refer to the provided security advisories for applicable patches and updates.
Multiple security vulnerabilities have been identified within Ivanti products. Specifically, versions of Neurons for ITSM (Cloud) and Sentry are affected. These vulnerabilities could allow an attacker to execute code remotely, elevate their privileges, and bypass security policies. The CERT-FR report highlights the following affected products and versions: Neurons for ITSM (Cloud) versions prior to 12.9.0.2, Sentry versions prior to R10.6.4, Sentry versions R10.7.x prior to R10.7.3, Sentry versions R10.8.x prior to R10.8.2, and Neurons for ITSM (On-Premises) versions 2025.2 and 2025.3 without the September 2026 security patch. The Ivanti Security Advisory---Ivanti-Endpoint-Manager-Mobile-CVE-2026-18851 and Security Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs are available for more details. The specific CVE identifiers are CVE-2026-18851 and CVE-2026-83527. Users are strongly recommended to consult the linked security advisories for detailed information and to apply the necessary updates immediately.