Multiple Remote Code Execution Vulnerabilities in Ivanti Neurons for ITSM
Multiple vulnerabilities in Ivanti Neurons for ITSM (CVE-2024-7569, CVE-2024-7570, CVE-2024-7571) allow a remote unauthenticated attacker to achieve remote code execution.
CVE search metadata
CVE search record: CVE-2024-7569. Severity: critical. CVSS: 9.6. EPSS: 1.74%. KEV: no. Product: Neurons for ITSM (<= 2023.4). Brief: Multiple Remote Code Execution Vulnerabilities in Ivanti Neurons for ITSM. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ivanti-it-rce/
CVE search record: CVE-2024-7570. Severity: high. CVSS: 8.3. EPSS: 0.57%. KEV: no. Product: Neurons for ITSM (<= 2023.4). Brief: Multiple Remote Code Execution Vulnerabilities in Ivanti Neurons for ITSM. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ivanti-it-rce/
CVE search record: CVE-2024-7571. Severity: high. CVSS: 7.8. EPSS: 0.26%. KEV: no. Product: Neurons for ITSM (<= 2023.4). Brief: Multiple Remote Code Execution Vulnerabilities in Ivanti Neurons for ITSM. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ivanti-it-rce/
Ivanti has disclosed multiple vulnerabilities affecting Ivanti Neurons for ITSM. These flaws include CVE-2024-7569, CVE-2024-7570, and CVE-2024-7571. These vulnerabilities reside within the ITSM application framework and, when successfully exploited, allow a remote, unauthenticated attacker to execute arbitrary code within the context of the application. Given the nature of ITSM platforms, which often run with elevated service account privileges, successful exploitation could lead to full application compromise, lateral movement within the network, and exfiltration of sensitive configuration or identity data stored within the ITSM database. Defenders should treat these vulnerabilities as high-priority targets for patching due to the potential for unauthenticated access.
Impact
Successful exploitation of these vulnerabilities allows an attacker to achieve remote code execution on the affected server. This could lead to a complete compromise of the Ivanti Neurons for ITSM instance, unauthorized access to sensitive service desk data, potential pivot points into the internal network, and the deployment of persistent backdoors.
Recommendation
Prioritize patching all internet-facing and internal instances of Ivanti Neurons for ITSM to the latest vendor-supplied version addressing CVE-2024-7569, CVE-2024-7570, and CVE-2024-7571. Ensure that service accounts used by the ITSM platform follow the principle of least privilege to minimize the impact of a potential RCE event. Restrict network access to the Ivanti Neurons for ITSM interface to authorized internal subnets via firewalls until updates can be applied.
Immediate actions
Patch Neurons for ITSM to 22.7R4 or later
Mitigations
Restrict external network access to Ivanti Neurons for ITSM web interface
CVE-2024-7569, CVE-2024-7570, CVE-2024-7571