Critical Security Updates for Ivanti Endpoint Manager Mobile, Neurons for ITSM, and Sentry
Ivanti released security patches for multiple products, including Endpoint Manager Mobile, Neurons for ITSM, and Sentry, addressing vulnerabilities identified as CVE-2026-18851 and CVE-2026-83527.
CVE search metadata
CVE search record: CVE-2026-18851. Severity: high. CVSS: 8.8. KEV: no. Product: Endpoint Manager Mobile (< 12.10.0.0, < 12.9.0.2, < 12.8.0.4), Neurons for ITSM (Cloud/SaaS < mo2026.2), Neurons for ITSM On-Prem (multiple versions < Sept 2026 patch), Sentry (< R10.8.2, < R10.7.3, < R10.6.4), Endpoint Manager Mobile. Brief: Critical Security Updates for Ivanti Endpoint Manager Mobile, Neurons for ITSM, and Sentry. Brief link: https://feed.craftedsignal.io/briefs/2026-09-08-ivanti-security-advisory/
CVE search record: CVE-2026-83527. Severity: high. CVSS: 8.1. KEV: no. Product: Endpoint Manager Mobile (< 12.10.0.0, < 12.9.0.2, < 12.8.0.4), Neurons for ITSM (Cloud/SaaS < mo2026.2), Neurons for ITSM On-Prem (multiple versions < Sept 2026 patch), Sentry (< R10.8.2, < R10.7.3, < R10.6.4), Endpoint Manager Mobile. Brief: Critical Security Updates for Ivanti Endpoint Manager Mobile, Neurons for ITSM, and Sentry. Brief link: https://feed.craftedsignal.io/briefs/2026-09-08-ivanti-security-advisory/
What's new
- 1. new product Sep 9, 12:49 via bsi
On September 8, 2026, Ivanti issued a comprehensive security advisory addressing multiple vulnerabilities across its product portfolio. The affected product families include Endpoint Manager Mobile, Neurons for ITSM (both Cloud/SaaS and On-Premises), and Sentry. Specific vulnerabilities disclosed include CVE-2026-18851, which impacts Endpoint Manager Mobile, and CVE-2026-83527, affecting Ivanti Sentry. These flaws pose significant security risks if left unpatched. Organizations are urged to review the vendor-provided advisories for each specific component and apply the necessary patches immediately to secure their infrastructure. The scope of affected versions is broad, necessitating a review of all current deployments to ensure they meet the minimum version requirements or include the September 2026 security patches.
Impact
Successful exploitation of these vulnerabilities could result in unauthorized access, potential remote code execution, or service disruption depending on the specific vulnerability and the impacted product. These Ivanti products are frequently used in enterprise environments for device management and service orchestration, making them high-value targets for threat actors seeking lateral movement or persistence within a network.
Recommendation
- Apply the September 2026 security patches to all affected Ivanti Neurons for ITSM (On-Prem) instances immediately.
- Upgrade Endpoint Manager Mobile to version 12.10.0.0, 12.9.0.2, or 12.8.0.4 or later.
- Update Ivanti Sentry environments to version R10.8.2, R10.7.3, or R10.6.4 or later.
- Ensure Neurons for ITSM (Cloud/SaaS) instances are at version mo2026.2 or later, as managed by the vendor.
- Monitor logs for the webserver category on these appliances for anomalous HTTP requests or unexpected system activity following the patch application.
Immediate actions
Patch all vulnerable Ivanti products to the specified versions or higher
Mitigations
Upgrade Ivanti products to patched versions
CVE-2026-18851, CVE-2026-83527