Ivanti has disclosed a high-severity improper access control vulnerability, CVE-2026-9614, in its Neurons for ITSM platform, affecting both cloud and on-premises deployments.
With a CVSS score of 8.8 (High), the flaw enables authenticated remote attackers to escalate privileges to the administrator level, potentially compromising entire IT service management environments.
Tracked as CVE-2026-9614, the flaw is classified under CWE-284 (Improper Access Control) and carries a CVSS 3.1 vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
This vector breakdown is particularly alarming for defenders, the attack is network-accessible, requires only low-level authentication, involves zero user interaction, and delivers high impact, Ivanti said.
An authenticated attacker with minimal privileges can traverse the access control boundary and acquire full administrative rights.
Ivanti published the official security advisory on June 1, 2026, reaffirming its policy of responsible transparency in disclosing product security issues.
Affected Versions
The vulnerability spans both deployment models:
| Deployment | Affected Version | Fixed Version |
|---|---|---|
| On-Premises | 2025.4 and prior | 2025.4 Patch 1, 2025.3 Patch 1, 2025.2 Patch 1 |
| Cloud (SaaS) | 2026.1 and prior | 2026.1 Patch 9, 2026.2 Patch 1 |
Ivanti confirmed at the time of disclosure that no customers have been actively exploited, the risk posture should not be understated. Ivanti products have historically been high-value targets for advanced persistent threat (APT) actors.
In early 2025, Ivanti’s Connect Secure platform was actively exploited via CVE-2025-0282, a critical stack-based buffer overflow that enabled threat actors to deploy web shells, disable SELinux, and wipe logs to evade detection.
The ITSM platform, which manages IT assets and service workflows across enterprises, represents an equally attractive target due to its deep integration with organizational infrastructure.
Mitigation
Ivanti’s recommended remediation strategy differs by deployment type:
- On-premises customers must manually download and apply the appropriate patch (2025.4 Patch 1, 2025.3 Patch 1, or 2025.2 Patch 1) from the Ivanti License System (ILS) Download Portal
- Cloud/SaaS customers require no action – Ivanti silently applied patches to all cloud landscapes on May 24 and 25, 2026
Organizations running Ivanti Neurons for ITSM on-premises should audit current-version deployments and patch them immediately. Security teams should also monitor for anomalous privilege changes or unusual admin-level API calls within ITSM environments.
Given the low attack complexity of CVE-2026-9614 and Ivanti’s track record as a favored target, unpatched internet-facing instances remain at elevated risk even in the absence of confirmed active exploitation.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.