Ivanti Security Update – 02 June 2026

Ivanti has released a security update to fix a vulnerability affecting Ivanti Neurons for ITSM versions 2025.4 and prior (On-Premises), versions 2026.1 and prior (Cloud).

The addressed vulnerability could allow the remote authenticated attacker to gain elevated privileges on the affected system.

The addressed vulnerability:

Ivanti Neurons for ITSM (Cloud and On-Premises) Improper Access Control Vulnerability (CVE-2026-9614):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges
Vulnerabilities

CVE-2026-8992

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Ivanti Security Advisory

References