{"id":1663,"date":"2026-09-15T12:47:29","date_gmt":"2026-09-15T07:17:29","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1663"},"modified":"2026-09-16T16:31:45","modified_gmt":"2026-09-16T11:01:45","slug":"ivanti-september-2026-security-patches-2","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/","title":{"rendered":"Ivanti Vulnerabilities: Critical ITSM RCE and Admin Access Flaws"},"content":{"rendered":"<h2>Introduction<\/h2>\n<p>Security tools need the same patching discipline as the systems they protect.<\/p>\n<p>On September 8, 2026, Ivanti released updates for ten vulnerabilities affecting Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM). The Ivanti vulnerabilities could enable remote code execution, authentication bypass, or administrative privilege escalation, depending on the affected product.<\/p>\n<p>Two Neurons for ITSM flaws and the Sentry vulnerability do not require authentication. That makes exposed or broadly accessible management interfaces particularly important to identify and patch. Ivanti had not reported evidence of exploitation before disclosure.<\/p>\n    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle  \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Who is Ivanti?<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tIvanti is an enterprise software vendor whose products support IT service management, endpoint management, mobile access, and related security operations. The products affected by the September 2026 advisories occupy privileged positions within enterprise environments.<\/p>\n<p>Neurons for ITSM manages service requests and IT workflows. EPMM provides mobile device and application management, while Sentry acts as a gateway between managed mobile devices and protected enterprise resources.<\/p>\n<p>These roles make access control and code execution flaws operationally significant. A successful attacker could potentially gain control over the affected product or interfere with administrative functions. However, these advisories describe software vulnerabilities rather than a confirmed attack campaign, and no threat actor has been attributed to them.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2>What happened?<\/h2>\n<p>Ivanti disclosed separate security advisories for Neurons for ITSM, Sentry, and EPMM. The flaws have different authentication requirements and should not be treated as a single attack chain.<\/p>\n<table>\n<thead>\n<tr>\n<th>Incident detail<\/th>\n<th>Verified information<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Disclosure date<\/td>\n<td>September 8, 2026<\/td>\n<\/tr>\n<tr>\n<td>Threat actor<\/td>\n<td>No threat actor or group has been identified<\/td>\n<\/tr>\n<tr>\n<td>Affected organizations<\/td>\n<td>Organizations operating vulnerable Neurons for ITSM, Sentry, or EPMM deployments<\/td>\n<\/tr>\n<tr>\n<td>Initial access<\/td>\n<td>Network access to the affected product is required; authentication requirements vary by vulnerability<\/td>\n<\/tr>\n<tr>\n<td>Social engineering<\/td>\n<td>None reported or required by the disclosed vulnerability conditions<\/td>\n<\/tr>\n<tr>\n<td>Credential or MFA impact<\/td>\n<td>No credential theft or MFA bypass was reported<\/td>\n<\/tr>\n<tr>\n<td>Persistence<\/td>\n<td>No persistence method was reported<\/td>\n<\/tr>\n<tr>\n<td>Data or access at risk<\/td>\n<td>Potential server-side code execution or administrative access, depending on the product<\/td>\n<\/tr>\n<tr>\n<td>Confirmed exploitation<\/td>\n<td>Ivanti reported no evidence that the flaws had been exploited before disclosure<\/td>\n<\/tr>\n<tr>\n<td>Confirmed impact<\/td>\n<td>The advisories confirm vulnerable software and potential impact, not a successful breach or data theft<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Eight Neurons for ITSM vulnerabilities<\/h2>\n<p>Neurons for ITSM received fixes for eight vulnerabilities: six critical flaws and two high-severity flaws. All eight could allow a remote attacker to execute arbitrary code on the affected server.<\/p>\n<p>CVE-2026-12744 and CVE-2026-12745 are critical deserialization-of-untrusted-data vulnerabilities with CVSS scores of 9.8. A remote attacker can exploit these flaws without authentication.<\/p>\n<p>CVE-2026-12645, CVE-2026-12646, and CVE-2026-12647 are missing-authorization vulnerabilities. CVE-2026-12650 is another deserialization flaw. These four critical vulnerabilities require authentication and carry CVSS scores of 9.9.<\/p>\n<p>CVE-2026-12648 and CVE-2026-12651 are high-severity deserialization vulnerabilities. Both require authentication and have CVSS scores of 8.8.<\/p>\n<p>Ivanti applied the fixes to its cloud-hosted Neurons for ITSM environments. Customers operating affected on-premises versions from the 2025.2 through 2026.1 release branches should install the relevant September 2026 security patches.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Key-Differences-Between-Signature-Based-and-Behavior-Based-Threat-Detection.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>What Are the Key Differences Between Signature-Based and Behaviour-Based Threat Detection?<\/h4><p>Compare signature- and behavior-based detection to understand their strengths, limitations, and use cases.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/signature-based-vs-behavior-based-detection\/\" aria-label=\"What Are the Key Differences Between Signature-Based and Behaviour-Based Threat Detection?\"><\/a><\/div><\/div><\/div><\/p>\n<h2>Ivanti Sentry CVE-2026-83527<\/h2>\n<p>Ivanti Sentry CVE-2026-83527 is a high-severity authentication bypass vulnerability rated 8.1. It affects Sentry deployments managed through EPMM or Neurons for MDM.<\/p>\n<p>A remote, unauthenticated attacker could exploit the flaw to obtain administrative-level access. This potential impact makes the vulnerability especially relevant to organizations that expose Sentry to untrusted networks.<\/p>\n<p>Ivanti addressed the flaw in Sentry R10.8.2, R10.7.3, and R10.6.4. Administrators should confirm their release branch and install the corresponding fixed version.<\/p>\n<h2>Ivanti EPMM CVE-2026-18851<\/h2>\n<p>Ivanti EPMM CVE-2026-18851 is a high-severity missing-authorization vulnerability rated 8.8. Unlike the Sentry flaw, it requires the attacker to authenticate before attempting exploitation.<\/p>\n<p>A remote authenticated attacker could exploit the vulnerability to elevate privileges to an administrator role. Therefore, describing it simply as an authentication bypass would be misleading: the weakness affects authorization after authentication.<\/p>\n<p>Ivanti fixed the flaw in EPMM 12.10.0.0, 12.9.0.2, and 12.8.0.4. Organizations running earlier builds within the affected release branches should upgrade to the appropriate fixed version.<\/p>\n<h2>Why this matters<\/h2>\n<p>ITSM, mobile management, and access gateways hold more authority than standard business applications. They may control device configurations, administrative workflows, application access, or connections to protected resources.<\/p>\n<p>As a result, a flaw in the management layer can create device management risk beyond the vulnerable server itself. Administrative access could let an attacker alter configurations or interfere with security operations. Remote code execution could also affect the confidentiality, integrity, and availability of the underlying server.<\/p>\n<p>Traditional endpoint controls cannot correct a vulnerability in an unpatched Ivanti product. Organizations need layered controls: vendor patching for the affected platform, restricted access to management interfaces, strong administrator authentication, least privilege, centralized logging, and monitoring for unexpected changes.<\/p>\n<p>The absence of reported exploitation should not delay remediation. It only means that exploitation had not been identified when the advisories were published.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-Unified-Endpoint-management_Brochures-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Hexnode-Unified-Endpoint-management_Brochures\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-Unified-Endpoint-management_Brochures-1.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-Unified-Endpoint-management_Brochures-1-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-Unified-Endpoint-management_Brochures-1-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-Unified-Endpoint-management_Brochures-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Hexnode-Unified-Endpoint-management_Brochures\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Feature Resource \n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why Hexnode UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Here's why UEM implementation might be the best thing for your organization right now\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/brochures\/why-hexnode-uem\/'>\n                            Get the Brochure\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>How Hexnode UEM Mitigates Admin Endpoint Risks<\/h2>\n<h3>Hexnode UEM: Maintain a separate endpoint security baseline<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a> helps organizations harden administrator workstations used to access Ivanti ITSM, Sentry, and EPMM consoles. Based on the device platform and management mode, administrators can enforce password requirements, encryption settings, application restrictions, and operating system update policies, helping mitigate credential theft and unauthorized console access.<\/p>\n<p>Application blocklists and allowlists can limit which software users can run on supported devices. This can reduce exposure to unauthorized applications on workstations used to access privileged management consoles.<\/p>\n<p>Hexnode\u2019s policy and compliance reports can show whether assigned configurations were applied successfully and identify non-compliant endpoints. Administrators can also scan managed devices to refresh information such as installed applications, system configurations, and current compliance status. In addition, Hexnode can enforce compliance-gated network access, preventing non-compliant or unpatched administrator devices from connecting to enterprise management networks.<\/p>\n<p>Audit reports provide a record of activity within the Hexnode console, including policy changes, app-management events, technician activity, and remote actions. These records can support internal reviews when security teams investigate unexpected management changes.<\/p>\n<p>However, Hexnode UEM does not remediate Ivanti Sentry, EPMM, or Neurons for ITSM vulnerabilities. Organizations must still apply Ivanti\u2019s product-specific patches and monitor the affected infrastructure. Hexnode provides an additional endpoint governance layer rather than a substitute for server patching or application security monitoring.<\/p>\n<h2>What security teams should do next<\/h2>\n<p>Start by creating an inventory of every Neurons for ITSM, Sentry, and EPMM deployment, including internally hosted instances. Record the installed release branch, exposure level, business owner, and patch status.<\/p>\n<p>Apply the appropriate enterprise security patches and verify that services return to a healthy state. Where immediate patching is not possible, restrict management interfaces to trusted networks and authorized administrators. These controls reduce exposure but do not replace the vendor update.<\/p>\n<p>Next, review administrator accounts, recent configuration changes, authentication records, and server logs for unexplained activity. Remove unnecessary accounts and validate that privileged users have only the access required for their roles.<\/p>\n<p>Audit administrator endpoints via Hexnode UEM to enforce mandatory OS and browser patching, strict application allowlisting, and console-access baselines.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try\u202fHexnode\u202fFree for 14 Days\u202f\u202f\u202f\u202f\u202f\u202f\u202f <\/h5><p>Strengthen endpoint security and compliance with Hexnode. Start your free trial today.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today\u202f\u202f<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction Security tools need the same patching discipline as the systems they protect. On September&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1702,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[18,21],"class_list":["post-1663","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mobile","category-patch-management","product_category-unified-endpoint-management","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Ivanti Vulnerabilities: September 2026 Patch Guide<\/title>\n<meta name=\"description\" content=\"Ivanti vulnerabilities in ITSM, Sentry and EPMM could enable code execution or admin access. Review affected versions and fixes.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ivanti Vulnerabilities: September 2026 Patch Guide\" \/>\n<meta property=\"og:description\" content=\"Ivanti vulnerabilities in ITSM, Sentry and EPMM could enable code execution or admin access. Review affected versions and fixes.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-15T07:17:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-16T11:01:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Ivanti-vulnerabilities.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ivanti-september-2026-security-patches-2\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ivanti-september-2026-security-patches-2\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"Ivanti Vulnerabilities: Critical ITSM RCE and Admin Access Flaws\",\"datePublished\":\"2026-09-15T07:17:29+00:00\",\"dateModified\":\"2026-09-16T11:01:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ivanti-september-2026-security-patches-2\\\/\"},\"wordCount\":1155,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ivanti-september-2026-security-patches-2\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Ivanti-vulnerabilities.png?format=webp\",\"articleSection\":[\"Mobile\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ivanti-september-2026-security-patches-2\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ivanti-september-2026-security-patches-2\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ivanti-september-2026-security-patches-2\\\/\",\"name\":\"Ivanti Vulnerabilities: September 2026 Patch Guide\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ivanti-september-2026-security-patches-2\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ivanti-september-2026-security-patches-2\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Ivanti-vulnerabilities.png?format=webp\",\"datePublished\":\"2026-09-15T07:17:29+00:00\",\"dateModified\":\"2026-09-16T11:01:45+00:00\",\"description\":\"Ivanti vulnerabilities in ITSM, Sentry and EPMM could enable code execution or admin access. Review affected versions and fixes.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ivanti-september-2026-security-patches-2\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ivanti-september-2026-security-patches-2\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ivanti-september-2026-security-patches-2\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Ivanti-vulnerabilities.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Ivanti-vulnerabilities.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Ivanti vulnerabilities\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ivanti-september-2026-security-patches-2\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Ivanti Vulnerabilities: Critical ITSM RCE and Admin Access Flaws\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"description\":\"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Ivanti Vulnerabilities: September 2026 Patch Guide","description":"Ivanti vulnerabilities in ITSM, Sentry and EPMM could enable code execution or admin access. Review affected versions and fixes.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/","og_locale":"en_US","og_type":"article","og_title":"Ivanti Vulnerabilities: September 2026 Patch Guide","og_description":"Ivanti vulnerabilities in ITSM, Sentry and EPMM could enable code execution or admin access. Review affected versions and fixes.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-15T07:17:29+00:00","article_modified_time":"2026-09-16T11:01:45+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Ivanti-vulnerabilities.png?format=webp","type":"image\/png"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"Ivanti Vulnerabilities: Critical ITSM RCE and Admin Access Flaws","datePublished":"2026-09-15T07:17:29+00:00","dateModified":"2026-09-16T11:01:45+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/"},"wordCount":1155,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Ivanti-vulnerabilities.png?format=webp","articleSection":["Mobile","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/","url":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/","name":"Ivanti Vulnerabilities: September 2026 Patch Guide","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Ivanti-vulnerabilities.png?format=webp","datePublished":"2026-09-15T07:17:29+00:00","dateModified":"2026-09-16T11:01:45+00:00","description":"Ivanti vulnerabilities in ITSM, Sentry and EPMM could enable code execution or admin access. Review affected versions and fixes.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Ivanti-vulnerabilities.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Ivanti-vulnerabilities.png?format=webp","width":1340,"height":700,"caption":"Ivanti vulnerabilities"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/ivanti-september-2026-security-patches-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Ivanti Vulnerabilities: Critical ITSM RCE and Admin Access Flaws"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"description":"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1663","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1663"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1663\/revisions"}],"predecessor-version":[{"id":1681,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1663\/revisions\/1681"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1702"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1663"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1663"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}