Skip to content
Threat Feed

Vendor

Ivanti

13 briefs RSS
high advisory

Multiple Remote Code Execution Vulnerabilities in Ivanti Neurons for ITSM

Multiple vulnerabilities in Ivanti Neurons for ITSM (CVE-2024-7569, CVE-2024-7570, CVE-2024-7571) allow a remote unauthenticated attacker to achieve remote code execution.

Neurons for ITSM vulnerability remote-code-execution ivanti
3c
high advisory

Critical Security Updates for Ivanti Endpoint Manager Mobile, Neurons for ITSM, and Sentry

Ivanti released security patches for multiple products, including Endpoint Manager Mobile, Neurons for ITSM, and Sentry, addressing vulnerabilities identified as CVE-2026-18851 and CVE-2026-83527.

Endpoint Manager Mobile +4 vulnerability patch-management security-advisory
2c updated
critical advisory

Unauthenticated RCE in Ivanti Connect Secure via CVE-2025-0282

A critical unauthenticated stack buffer overflow in Ivanti Connect Secure, Policy Secure, and Neurons for Zero-trust Access (version 22.7) allows remote attackers to execute arbitrary code and create unauthorized administrative accounts.

Connect Secure +2 vulnerability remote-code-execution ivanti
2t 1c
medium advisory

Ivanti Xtraction Vulnerabilities CVE-2026-14902 and CVE-2026-14903

Ivanti has published a security advisory (AV26-696) on July 14, 2026, to address two vulnerabilities, CVE-2026-14902 and CVE-2026-14903, affecting Ivanti Xtraction version 2026.2 and prior, urging users to apply necessary updates to mitigate potential risks.

Ivanti Xtraction vulnerability Ivanti security-advisory
2c
high threat

ServiceNow Critical Sandbox Escape Vulnerability (CVE-2026-6875)

ServiceNow has released a security advisory addressing CVE-2026-6875, a critical sandbox escape vulnerability affecting multiple product versions including Brazil, Australia, Zurich, and Yokohama, which could allow an attacker to bypass security boundaries and execute arbitrary code with elevated privileges.

exploited Brazil +18 vulnerability servicenow cloud
3c updated
high threat

ESET APT Activity Report Q4 2025–Q1 2026 Highlights Various Threat Actor Campaigns

ESET's APT Activity Report for Q4 2025 and Q1 2026 highlights diverse campaigns by China, Iran, North Korea, and Russia-aligned threat actors, including espionage, supply chain compromise, and destructive attacks.

Ivanti VPN appliances +2 Lazarus Group +4 apt espionage supply-chain wiper
2r 3t
medium advisory

Ivanti Secure Access Client: Local Privilege Escalation Vulnerabilities

A local attacker can exploit vulnerabilities in Ivanti Secure Access Client to manipulate files or escalate privileges, potentially gaining elevated access to the system.

Secure Access Client privilege-escalation ivanti windows linux macos
2r 1t
medium advisory

Ivanti Addresses Multiple Vulnerabilities in Various Products

Ivanti released security advisories on May 12, 2026, to address vulnerabilities in Xtraction, Endpoint Manager (EPM), Virtual Traffic Manager (vTM), and Secure Access Client (Windows), urging users to apply necessary updates to mitigate potential risks from CVE-2026-8043, CVE-2026-8051, CVE-2026-7431, and CVE-2026-7432.

Xtraction +3 ivanti vulnerability patch cve
2r 4c
critical advisory

Multiple Vulnerabilities in Ivanti Endpoint Manager Mobile

Multiple vulnerabilities in Ivanti Endpoint Manager Mobile allow an attacker to gain administrator privileges, execute arbitrary code with administrator privileges, bypass security measures, manipulate data, and disclose sensitive information.

Endpoint Manager Mobile vulnerability privilege-escalation execution
2r 4t
critical threat

Ivanti EPMM Authenticated Remote Code Execution Vulnerability Exploited

CVE-2026-6973, an authenticated remote code execution vulnerability in Ivanti Endpoint Manager Mobile (EPMM), is being actively exploited, potentially leading to data breaches and system compromise.

exploited Endpoint Manager Mobile ivanti eppm rce vulnerability exploitation
2r 4t 1c
critical advisory

Ivanti VTM Administrator Account Creation via CVE-2024-7593

Unauthenticated remote attackers are exploiting CVE-2024-7593 in Ivanti Virtual Traffic Manager (vTM) to bypass authentication and create new administrator accounts, potentially leading to full system compromise.

Ivanti Virtual Traffic Manager ivanti cve-2024-7593 authentication-bypass account-creation
2r 2t 1c
high advisory

DNS Kerberos Coercion Attempt Detection

This brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.

PoC Fortinet edge appliances +38 kerberos coercion dns cve-2025-33073
3r 3t 4c 4i updated
critical threat

Ivanti EPMM Unauthenticated API Access via CVE-2023-35078

Exploitation of CVE-2023-35078 in Ivanti EPMM allows unauthenticated remote API access, potentially leading to data theft, unauthorized modifications, or further system compromise.

PoC Endpoint Manager Mobile ivanti epmm cve-2023-35078 unauthenticated-access
2r 2t 1c updated