{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/neurons-for-itsm-on-prem-multiple-versions--sept-2026-patch/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-18851"},{"cvss":8.1,"id":"CVE-2026-83527"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Endpoint Manager Mobile (\u003c 12.10.0.0, \u003c 12.9.0.2, \u003c 12.8.0.4)","Neurons for ITSM (Cloud/SaaS \u003c mo2026.2)","Neurons for ITSM On-Prem (multiple versions \u003c Sept 2026 patch)","Sentry (\u003c R10.8.2, \u003c R10.7.3, \u003c R10.6.4)","Endpoint Manager Mobile"],"_cs_severities":["high"],"_cs_tags":["vulnerability","patch-management","security-advisory"],"_cs_type":"advisory","_cs_vendors":["Ivanti"],"content_html":"\u003cp\u003eOn September 8, 2026, Ivanti issued a comprehensive security advisory addressing multiple vulnerabilities across its product portfolio. The affected product families include Endpoint Manager Mobile, Neurons for ITSM (both Cloud/SaaS and On-Premises), and Sentry. Specific vulnerabilities disclosed include CVE-2026-18851, which impacts Endpoint Manager Mobile, and CVE-2026-83527, affecting Ivanti Sentry. These flaws pose significant security risks if left unpatched. Organizations are urged to review the vendor-provided advisories for each specific component and apply the necessary patches immediately to secure their infrastructure. The scope of affected versions is broad, necessitating a review of all current deployments to ensure they meet the minimum version requirements or include the September 2026 security patches.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in unauthorized access, potential remote code execution, or service disruption depending on the specific vulnerability and the impacted product. These Ivanti products are frequently used in enterprise environments for device management and service orchestration, making them high-value targets for threat actors seeking lateral movement or persistence within a network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the September 2026 security patches to all affected Ivanti Neurons for ITSM (On-Prem) instances immediately.\u003c/li\u003e\n\u003cli\u003eUpgrade Endpoint Manager Mobile to version 12.10.0.0, 12.9.0.2, or 12.8.0.4 or later.\u003c/li\u003e\n\u003cli\u003eUpdate Ivanti Sentry environments to version R10.8.2, R10.7.3, or R10.6.4 or later.\u003c/li\u003e\n\u003cli\u003eEnsure Neurons for ITSM (Cloud/SaaS) instances are at version mo2026.2 or later, as managed by the vendor.\u003c/li\u003e\n\u003cli\u003eMonitor logs for the webserver category on these appliances for anomalous HTTP requests or unexpected system activity following the patch application.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T12:49:22Z","date_published":"2026-09-08T22:23:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-08-ivanti-security-advisory/","summary":"Ivanti released security patches for multiple products, including Endpoint Manager Mobile, Neurons for ITSM, and Sentry, addressing vulnerabilities identified as CVE-2026-18851 and CVE-2026-83527.","title":"Critical Security Updates for Ivanti Endpoint Manager Mobile, Neurons for ITSM, and Sentry","url":"https://feed.craftedsignal.io/briefs/2026-09-08-ivanti-security-advisory/"}],"language":"en","title":"CraftedSignal Threat Feed - Neurons for ITSM On-Prem (Multiple Versions \u003c Sept 2026 Patch)","version":"https://jsonfeed.org/version/1.1"}