These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-12745 is a Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before version 2026.2. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary code on the server. The vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. Ivanti Neurons for ITSM administrators and users, as well as security teams responsible for monitoring and prot [truncated]
CVE-2026-12744 is a Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before version 2026.2. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary code on the server. The CVE record was published on 2026-09-08T15:18:41.080Z and was last modified on 2026-09-18T17:56:12.373Z. The NVD entry is currently Analyzed.
CVE-2026-12651 is a Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before version 2026.2. A remote authenticated attacker can exploit this vulnerability to execute arbitrary code on the server. The CVE record was published on 2026-09-08T15:18:40.963Z and was last modified on 2026-09-18T17:58:04.570Z. The NVD entry is currently Analyzed.
CVE-2026-12650 is a Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before version 2026.2. A remote authenticated attacker can exploit this vulnerability to execute arbitrary code on the server. The CVE record was published on 2026-09-08T15:18:40.850Z and was last modified on 2026-09-18T18:07:30.283Z. The NVD entry is currently Analyzed.
CVE-2026-12648 is a Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before version 2026.2. A remote authenticated attacker can exploit this vulnerability to execute arbitrary code on the server. The CVE record was published on 2026-09-08T15:18:40.733Z and was last modified on 2026-09-18T18:05:15.220Z. The NVD entry is currently Analyzed.
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. This CVE record was published on 2026-09-08T15:18:40.623Z and was last modified on 2026-09-18T18:14:02.137Z. The NVD entry is currently Analyzed. The vulnerability affects Ivanti Neurons for ITSM versions prior to 2026.2, and administrators should a [truncated]
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. This CVE record was published on 2026-09-08T15:18:40.507Z and was last modified on 2026-09-18T18:15:33.707Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS score of 9.9 and is considered Critical. IT administrators and security te [truncated]
CVE-2026-12645 is a Missing Authorization vulnerability in Ivanti Neurons for ITSM before version 2026.2. A remote authenticated attacker can exploit this vulnerability to execute arbitrary code on the server. The vulnerability has a CVSS score of 9.9 and is considered CRITICAL. Ivanti Neurons for ITSM administrators and security teams should assess exposure and apply patches or mitigations. Verify Ivanti [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T15:17:28.193Z and has not been modified since then. CVE-2026-18127 is a vulnerability in Ivanti Endpoint Manager that allows a remote authenticated attacker to control a filename, potentially leading to full write control over an S3 bucket configured for session recording storage. The vulnerabili [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T15:16:57.113Z and has not been modified since then. The vulnerability is a path traversal issue in Ivanti Xtraction before version 2026.2.1, allowing a remote authenticated attacker to read arbitrary files outside the web root. This issue is classified under CWE-22 and CWE-23. Organizations using [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T15:16:56.977Z and has not been modified since then. CVE-2026-14902 is an open redirect vulnerability in Ivanti Xtraction before version 2026.2.1. A remote unauthenticated attacker can redirect users to arbitrary external URLs. The vulnerability has a CVSS score of 4 and a severity of MEDIUM. Affe [truncated]
CVE-2026-8992 is an improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6. This vulnerability allows a remote unauthenticated attacker to execute arbitrary code. The CVE record was published on 2026-05-22T15:16:26.963Z and was last modified on 2026-07-23T16:10:00.137Z. Organizations should review their Ivanti Secure Access Client deployments and ensure they are updated [truncated]
CVE-2026-6973 is an Ivanti Endpoint Manager Mobile (EPMM) vulnerability described as improper input validation. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-05-07, which means it is treated as a known-exploited issue and should be addressed urgently. The supplied corpus does not include deeper technical detail or a CVSS score, so defensive response should focus on confirming exposu [truncated]
CVE-2026-1340 is a code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that CISA added to the Known Exploited Vulnerabilities catalog on 2026-04-08. The supplied CISA guidance emphasizes assessing exposure, checking internet-accessible affected products for signs of compromise, and applying vendor mitigations as soon as possible. If mitigations are unavailable, CISA advises discontinuing [truncated]
CVE-2026-1603 is a known-exploited authentication bypass vulnerability in Ivanti Endpoint Manager (EPM). CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-09 and set a remediation due date of 2026-03-23, so affected organizations should treat mitigation as urgent.
CVE-2026-1281 is an Ivanti Endpoint Manager Mobile (EPMM) code injection vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2026-01-29. The supplied authoritative material does not provide root-cause, precondition, or impact specifics beyond the code-injection classification. Because it is KEV-listed, defenders should treat it as urgent, verify exposure, apply vendor mitigatio [truncated]
CVE-2025-4428 is a code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM). CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-19 and set a remediation due date of 2025-06-09, so organizations using EPMM should treat it as a high-priority exposure and apply vendor mitigations or discontinue use if mitigations are unavailable.
CVE-2025-4427 is an authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM). CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2025-05-19, indicating it is treated as a vulnerability with known exploitation risk. The KEV entry directs defenders to apply vendor mitigations, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if [truncated]
CVE-2025-22457 affects Ivanti Connect Secure, Policy Secure, and ZTA Gateways and is described as a stack-based buffer overflow vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-04-04, which indicates confirmed real-world exploitation. CISA also marks the issue as having known ransomware campaign use, so exposed Ivanti gateway deployments should be treated as urgent remed [truncated]
CVE-2024-13161 is an absolute path traversal vulnerability affecting Ivanti Endpoint Manager (EPM). CISA added the issue to its Known Exploited Vulnerabilities catalog on 2025-03-10, which makes this a priority item for exposed Ivanti EPM environments.
CVE-2024-13160 is a vendor-identified absolute path traversal issue in Ivanti Endpoint Manager (EPM) that CISA added to the Known Exploited Vulnerabilities catalog on 2025-03-10. Because CISA classifies it as known exploited, this should be treated as an urgent remediation item. The supplied corpus directs defenders to apply vendor mitigations per Ivanti's instructions, and to discontinue use of the produ [truncated]
CVE-2024-13159 is an Ivanti Endpoint Manager (EPM) absolute path traversal vulnerability. CISA added the issue to its Known Exploited Vulnerabilities (KEV) catalog on 2025-03-10, which means defenders should treat it as a high-priority remediation item. The public sources provided here do not include a CVSS score, and the most actionable guidance is to follow vendor mitigation instructions and, where appl [truncated]
CVE-2025-0282 is a publicly listed Ivanti vulnerability affecting Connect Secure, Policy Secure, and ZTA Gateways. The supplied corpus identifies it as a stack-based buffer overflow and shows that CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-08, with a remediation due date of 2025-01-15. Because it is in KEV and marked as known ransomware campaign use, defenders should treat it [truncated]
CVE-2024-9380 affects Ivanti Cloud Services Appliance (CSA) and is described as an OS command injection vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-09, so defenders should treat it as a known-exploited issue and prioritize remediation. CISA’s KEV entry also says CSA 4.6.x has reached end-of-life status and should be removed from service or upgraded to the 5.0.x l [truncated]
CVE-2024-9379 affects Ivanti Cloud Services Appliance (CSA) and is listed by CISA as a known exploited vulnerability. CISA added it to the KEV catalog on 2024-10-09 and set a remediation due date of 2024-10-30. For CSA 4.6.x, CISA's required action is to remove it from service or upgrade to the 5.0.x line or later.
CVE-2024-29824 affects Ivanti Endpoint Manager (EPM) and is listed by CISA in the Known Exploited Vulnerabilities catalog, which means CISA has assessed it as actively exploited. The supplied source data does not include a CVSS score or detailed technical impact, but it does provide a clear defensive directive: apply vendor mitigations or discontinue use of the product if mitigations are unavailable. Beca [truncated]
CVE-2024-7593 is an Ivanti Virtual Traffic Manager authentication bypass issue that CISA added to the Known Exploited Vulnerabilities catalog on 2024-09-24. Because it is KEV-listed, organizations should treat it as a high-priority remediation item and follow Ivanti’s mitigation guidance immediately. If mitigations are not available or cannot be applied promptly, CISA’s guidance is to discontinue use of the product.
CVE-2024-8963 is a path traversal vulnerability affecting Ivanti Cloud Services Appliance (CSA). CISA added the issue to its Known Exploited Vulnerabilities catalog on 2024-09-19, which means defenders should treat it as actively prioritized for remediation. CISA’s guidance notes that Ivanti CSA 4.6.x has reached end-of-life status and should be removed from service or upgraded to the supported 5.0.x line.
CVE-2024-8190 is an Ivanti Cloud Services Appliance (CSA) OS command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-09-13. Because Ivanti CSA 4.6.x has reached end-of-life, CISA urges organizations to remove CSA 4.6.x from service or upgrade to the supported 5.0.x line. The available source corpus does not provide a CVSS score, but the KEV listing means the [truncated]
CVE-2021-44529 is a code injection vulnerability affecting Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA). CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2024-03-25, set a remediation due date of 2024-04-15, and marked the entry as having known ransomware campaign use. From a defensive standpoint, that makes this a high-priority remediation item for any organization runni [truncated]