Skip to content
Threat Feed
high advisory

Multiple Remote Code Execution Vulnerabilities in Ivanti Neurons for ITSM

Multiple vulnerabilities in Ivanti Neurons for ITSM (CVE-2024-7569, CVE-2024-7570, CVE-2024-7571) allow a remote unauthenticated attacker to achieve remote code execution.

CVE search metadata

CVE search record: CVE-2024-7569. Severity: critical. CVSS: 9.6. EPSS: 1.74%. KEV: no. Product: Neurons for ITSM (<= 2023.4). Brief: Multiple Remote Code Execution Vulnerabilities in Ivanti Neurons for ITSM. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ivanti-it-rce/

CVE search record: CVE-2024-7570. Severity: high. CVSS: 8.3. EPSS: 0.57%. KEV: no. Product: Neurons for ITSM (<= 2023.4). Brief: Multiple Remote Code Execution Vulnerabilities in Ivanti Neurons for ITSM. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ivanti-it-rce/

CVE search record: CVE-2024-7571. Severity: high. CVSS: 7.8. EPSS: 0.26%. KEV: no. Product: Neurons for ITSM (<= 2023.4). Brief: Multiple Remote Code Execution Vulnerabilities in Ivanti Neurons for ITSM. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ivanti-it-rce/

Ivanti has disclosed multiple vulnerabilities affecting Ivanti Neurons for ITSM. These flaws include CVE-2024-7569, CVE-2024-7570, and CVE-2024-7571. These vulnerabilities reside within the ITSM application framework and, when successfully exploited, allow a remote, unauthenticated attacker to execute arbitrary code within the context of the application. Given the nature of ITSM platforms, which often run with elevated service account privileges, successful exploitation could lead to full application compromise, lateral movement within the network, and exfiltration of sensitive configuration or identity data stored within the ITSM database. Defenders should treat these vulnerabilities as high-priority targets for patching due to the potential for unauthenticated access.

Impact

Successful exploitation of these vulnerabilities allows an attacker to achieve remote code execution on the affected server. This could lead to a complete compromise of the Ivanti Neurons for ITSM instance, unauthorized access to sensitive service desk data, potential pivot points into the internal network, and the deployment of persistent backdoors.

Recommendation

Prioritize patching all internet-facing and internal instances of Ivanti Neurons for ITSM to the latest vendor-supplied version addressing CVE-2024-7569, CVE-2024-7570, and CVE-2024-7571. Ensure that service accounts used by the ITSM platform follow the principle of least privilege to minimize the impact of a potential RCE event. Restrict network access to the Ivanti Neurons for ITSM interface to authorized internal subnets via firewalls until updates can be applied.


Immediate actions

Patch Neurons for ITSM to 22.7R4 or later

IT Operations 24h

Mitigations

Restrict external network access to Ivanti Neurons for ITSM web interface

immediate Network Security

CVE-2024-7569, CVE-2024-7570, CVE-2024-7571