Forkast.News
Ivanti Discloses Critical Authentication Bypass Vulnerabilities
Article Content
On September 8, 2026, Ivanti disclosed multiple vulnerabilities affecting its Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry products. Two critical CVEs, CVE-2026-83527 and CVE-2026-18851, allow for authentication bypass and privilege escalation, respectively. CVE-2026-83527 has a CVSS score of 8.1, enabling remote attackers to gain administrative access without credentials. CVE-2026-18851, with a CVSS of 8.8, requires initial authentication but allows escalation to full admin privileges. The broader disclosure includes ten CVEs, with several rated critical, indicating a significant security gap across Ivanti's management stack. None of the vulnerabilities were reported to be exploited in the wild prior to disclosure, but the history of similar vulnerabilities raises concerns. Organizations using affected versions are urged to apply patches immediately to mitigate risks.
Key Points: • Two critical vulnerabilities allow for authentication bypass and privilege escalation. • CVE-2026-83527 enables remote administrative access without credentials. • Patching is essential as none of the vulnerabilities were exploited before disclosure.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.