Ivanti Discloses Critical Authentication Bypass Vulnerabilities

Ivanti Discloses Critical Authentication Bypass Vulnerabilities

First seen 9 Sep 2026, 15:48 UTC CybersecuritynewsForkast.News 60.6

Article Content

Browse articles
ThreatCluster

On September 8, 2026, Ivanti disclosed multiple vulnerabilities affecting its Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry products. Two critical CVEs, CVE-2026-83527 and CVE-2026-18851, allow for authentication bypass and privilege escalation, respectively. CVE-2026-83527 has a CVSS score of 8.1, enabling remote attackers to gain administrative access without credentials. CVE-2026-18851, with a CVSS of 8.8, requires initial authentication but allows escalation to full admin privileges. The broader disclosure includes ten CVEs, with several rated critical, indicating a significant security gap across Ivanti's management stack. None of the vulnerabilities were reported to be exploited in the wild prior to disclosure, but the history of similar vulnerabilities raises concerns. Organizations using affected versions are urged to apply patches immediately to mitigate risks.

Key Points: • Two critical vulnerabilities allow for authentication bypass and privilege escalation. • CVE-2026-83527 enables remote administrative access without credentials. • Patching is essential as none of the vulnerabilities were exploited before disclosure.

Ask AI about this cluster

Timeline

2023-08-21
CVE-2023-38035 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-04-24
CVE-2025-31324 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-29
CVE-2026-1281 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-07
CVE-2026-6973 published
This vulnerability was added to the CISA KEV list, indicating active exploitation in the wild.
Forkast.News
2026-06-09
CVE-2026-10523 published
Ivanti disclosed another authentication bypass vulnerability in Sentry, highlighting ongoing security issues.
Forkast.News
2026-06-09
CVE-2026-10520 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
Ivanti discloses multiple vulnerabilities
Ivanti announced ten CVEs affecting EPMM, Neurons for ITSM, and Sentry, including critical authentication bypasses.
Cybersecuritynews
2026-09-08
CVE-2026-83527 and CVE-2026-18851 published
CVE-2026-83527 allows unauthenticated access, while CVE-2026-18851 enables privilege escalation after initial authentication.
Forkast.News
2026-09-08
CVE-2026-12744 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-12745 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE