Full Report
Ivanti security advisory (AV26-897)
Analysis Summary
# Vulnerability: Ivanti September 2026 Multi-Product Security Updates
## CVE Details
- **CVE ID:** CVE-2026-18851, CVE-2026-83527, and [Multiple CVEs for ITSM]
- **CVSS Score:** Up to 9.8 (Critical) - *Estimated based on typical Ivanti critical advisory profiles for these product lines.*
- **CWE:** Not explicitly specified in the summary, typically includes Injection or Authentication Bypass patterns.
## Affected Systems
- **Products:** Ivanti Endpoint Manager Mobile (EPMM), Neurons for ITSM (Cloud & On-Prem), and Ivanti Sentry.
- **Versions:**
- **EPMM:** Prior to 12.10.0.0, 12.9.0.2, and 12.8.0.4.
- **Neurons for ITSM (Cloud):** Prior to mo2026.2.
- **Neurons for ITSM (On-Prem):** Prior to 2025.2, 2025.3, 2025.4, 2026.1 (Sept 2026 Patch levels), and 2026.2.
- **Sentry:** Prior to R10.8.2, R10.7.3, and R10.6.4.
- **Configurations:** Default installations of the listed versions.
## Vulnerability Description
While the brief advisory focuses on versioning, these flaws represent significant security gaps in Ivanti's mobile device management and service management ecosystems.
- **CVE-2026-18851 (EPMM):** Typically involves unauthorized access or remote code execution capabilities within the mobile management interface.
- **CVE-2026-83527 (Sentry):** Often relates to bypasses in the secure gateway designed to manage and encrypt traffic between devices and backend systems.
- **Neurons for ITSM Flaws:** A cluster of vulnerabilities affecting the service management platform's data handling and user authentication.
## Exploitation
- **Status:** Not explicitly stated as "Exploited in the wild" in this bulletin, but Ivanti products are frequent targets for advanced persistent threats (APTs).
- **Complexity:** Low to Medium.
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Potential access to sensitive corporate mobile data and ITSM records).
- **Integrity:** High (Potential unauthorized modification of system configurations).
- **Availability:** High (Potential for service disruption).
## Remediation
### Patches
Ivanti recommends upgrading to the following versions or higher:
- **EPMM:** 12.10.0.0, 12.9.0.2, or 12.8.0.4.
- **Neurons for ITSM (Cloud):** mo2026.2.
- **Neurons for ITSM (On-Prem):** 2026.2 or the specific September 2026 Security Patches for versions 2025.x/2026.1.
- **Sentry:** R10.8.2, R10.7.3, or R10.6.4.
### Workarounds
- No specific workarounds are provided in the high-level advisory; immediate patching is the primary recommended defense.
- Restrict access to management interfaces to trusted internal networks/VPNs.
## Detection
- **Indicators of Compromise:** Monitor for unusual administrative logins, unauthorized configuration changes in EPMM, or unexpected outbound traffic from Sentry appliances.
- **Detection methods:** Review system logs for the specific CVE identifiers post-scan using vulnerability management tools.
## References
- Ivanti Neurons for ITSM Advisory: hxxps[://]hub[.]ivanti[.]com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US
- Ivanti EPMM Advisory: hxxps[://]hub[.]ivanti[.]com/s/article/Security-Advisory---Ivanti-Endpoint-Manager-Mobile-CVE-2026-18851?language=en_US
- Ivanti Sentry Advisory: hxxps[://]hub[.]ivanti[.]com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-83527?language=en_US
- Ivanti Blog Summary: hxxps[://]www[.]ivanti[.]com/blog/september-2026-security-update