#IvantiFix
Two vulnerabilities in Ivanti Neurons ITSM (CVE-2026-4913 & CVE-2026-4914) allow session persistence and stored XSS to expose session data. Cloud fixes released Dec 12, 2025; on-prem users must update via Ivanti License System. #IvantiFix #SessionHijack
Ivanti Neurons ITSM Vulnerabilities Could Allow Session Persistence
Two newly disclosed vulnerabilities in Ivanti Neurons for IT Service Management (CVE-2026-4913 and CVE-2026-4914) could allow authenticated attackers to persist in user sessions or inject stored XSS payloads to expose session data. Ivanti has applied cloud fixes on December 12, 2025 and released a patched version 2025.4 for all customers, with...
www.hendryadrian.com
April 15, 2026 at 2:45 PM