# ANSSI Flags Multiple Ivanti Product Vulnerabilities

Published: 2026-09-09 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/c2d365c3-34cf-5402-b24f-0563d8fd4e18/anssi-flags-multiple-ivanti-product-vulnerabilities

> ANSSI advisory details multiple vulnerabilities in Ivanti EPMM, Neurons for ITSM, and Sentry allowing RCE, privilege escalation, and security bypass.

The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory covering multiple vulnerabilities affecting several Ivanti enterprise products: Endpoint Manager Mobile (EPMM), Neurons for ITSM (both cloud and on-premises deployments), and Sentry. The flaws collectively allow an attacker to bypass security policy, execute arbitrary code remotely, and escalate privileges. Two CVEs are explicitly referenced: CVE-2026-18851 (affecting EPMM) and CVE-2026-83527 (affecting Sentry), with additional unspecified CVEs affecting Neurons for ITSM covered by a separate multi-CVE bulletin from Ivanti.

Affected versions include EPMM 12.9.x prior to 12.9.0.2 and versions prior to 12.8.0.4; Neurons for ITSM Cloud version 2026.2 prior to mo2026.2, and several on-premises ITSM versions (2025.2, 2025.3, 2025.4, 2026.1) lacking the September 2026 security patch; and Sentry versions prior to R10.6.4, R10.7.x prior to R10.7.3, and R10.8.x prior to R10.8.2. The vendor states that cloud-hosted Neurons for ITSM instances have already been patched by Ivanti. No indication of active exploitation is provided in this advisory; it is a routine vendor patch bulletin republished by CERT-FR. Defenders operating on-premises Ivanti EPMM, Neurons for ITSM, or Sentry should apply the September 2026 vendor patches promptly given Ivanti products' history as frequent targets for exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-18851, CVE-2026-83527

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1135

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c2d365c3-34cf-5402-b24f-0563d8fd4e18/anssi-flags-multiple-ivanti-product-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
