Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-9614 |
| Alert Source | Ivanti Security Advisory |
| CVE Publication Year | 2026 |
| Date Published | 2026-06-04 |
| Vendor | Ivanti |
| Product | Neurons for ITSM |
| CVSS Score | 8.0 (high) |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
A high-severity privilege escalation vulnerability has been identified in Ivanti Neurons for ITSM, a widely used IT service management platform. An authenticated attacker can exploit the flaw to gain elevated privileges on affected systems, potentially gaining unauthorized access to sensitive platform functions and data. Successful exploitation impacts the security and integrity of the ITSM environment.
Affected products and versions:
- Ivanti Neurons for ITSM (On-Premises) — versions up to and including 2025.4
- Ivanti Neurons for ITSM (Cloud) — versions up to and including 2026.1
Required Actions
Update Ivanti Neurons for ITSM promptly to the vendor-fixed versions. Review administrator and privileged account activity for signs of abuse and apply least-privilege principles to ITSM access.
Who Is Affected?
This vulnerability affects Neurons for ITSM by Ivanti. Check if your organization runs an affected On-Premises (≤ 2025.4) or Cloud (≤ 2026.1) version and apply the vendor-fixed release.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
