Ivanti Neurons for ITSM contains a security policy bypass vulnerability (CVE-2026-9614)…
Ivanti Neurons for ITSM contains a security policy bypass vulnerability (CVE-2026-9614) affecting both cloud and on-premises versions; patches available.
The French CERT has issued an advisory regarding a security policy bypass vulnerability in Ivanti Neurons for ITSM products. The vulnerability, tracked as CVE-2026-9614, affects multiple versions of both cloud-based and on-premises deployments. Affected versions include Neurons for ITSM Cloud 2026.1 (prior to patch 9) and 2026.2 (prior to patch 1), as well as on-premises versions 2025.2, 2025.3, and 2025.4 (all prior to their respective patch 1 releases).
The vulnerability allows an attacker to bypass security policies, though specific exploitation details and attack vectors are not provided in the advisory. Ivanti has released security updates to address this issue, published on June 1, 2026. Organizations running affected versions should refer to Ivanti's security bulletins and apply the appropriate patches immediately.
Given that ITSM platforms typically handle sensitive IT infrastructure data and service management workflows, a security policy bypass could potentially allow unauthorized access to critical systems or data. The availability of patches indicates this is a known and addressable issue requiring prompt remediation.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0677
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free