AI Security AI安全 1d ago Updated 17h ago 更新于 17小时前 43

Ivanti Patches Critical Flaws Across Enterprise Security Products Ivanti 修复企业安全产品中的关键漏洞

Ivanti released security patches for critical and high-severity vulnerabilities across Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) Neurons for ITSM received the most fixes: eight bugs total, six rated critical, including missing authorization flaws (CVSS 9.9) and unsafe deserialization issues leading to remote code execution Two vulnerabilities (CVE-2026-12744 and CVE-2026-12745) can be exploited without authentication, making them particularly dangerous Sentry and EPMM each rec Ivanti发布安全更新,修复Neurons for ITSM中8个安全漏洞,其中6个为严重级别,可导致远程代码执行 Sentry和EPMM产品分别修复了高严重性认证绕过漏洞(CVE-2026-83527和CVE-2026-18851) 部分漏洞(CVE-2026-12744和CVE-2026-12745)可在无需认证的情况下被利用,CVSS评分高达9.9 Ivanti确认目前未发现这些漏洞在野外被利用的情况 Citrix同步修复了Workspace app的两个中等严重性漏洞

68
Hot 热度
58
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • Ivanti released security patches for critical and high-severity vulnerabilities across Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM)
  • Neurons for ITSM received the most fixes: eight bugs total, six rated critical, including missing authorization flaws (CVSS 9.9) and unsafe deserialization issues leading to remote code execution
  • Two vulnerabilities (CVE-2026-12744 and CVE-2026-12745) can be exploited without authentication, making them particularly dangerous
  • Sentry and EPMM each received patches for high-severity authentication bypass vulnerabilities (CVE-2026-83527 and CVE-2026-18851 respectively)
  • Ivanti reports no known active exploitation in the wild; updates are available for multiple product versions

Why It Matters

This is a significant security event for organizations relying on Ivanti's IT service management and endpoint management platforms, as multiple critical vulnerabilities could allow unauthenticated remote code execution. The fact that some flaws require no authentication makes immediate patching essential for on-premises deployments. IT security teams should treat this as a priority update cycle to prevent potential compromise of enterprise IT infrastructure.

Technical Details

  • Neurons for ITSM: Eight vulnerabilities patched across versions 2025.2, 2025.3, 2025.4, and 2026.1 (with 2026.2 scheduled for September 21). Six critical flaws include CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646 (missing authorization, CVSS 9.9) and CVE-2026-12650, CVE-2026-12744, CVE-2026-12745 (deserialization of untrusted data, CVSS 9.8-9.9). Two high-severity deserialization bugs (CVE-2026-12651, CVE-2026-12648) also enable remote code execution.
  • Sentry: Versions R10.8.2, R10.7.3, and R10.6.4 patch CVE-2026-83527, a high-severity authentication bypass allowing unauthenticated attackers to gain administrative privileges.
  • EPMM: Versions 12.10.0.0, 12.9.0.2, and 12.8.0.4 address CVE-2026-18851, a high-severity authentication bypass that requires prior authentication for exploitation.
  • All vulnerabilities were disclosed through Ivanti's advisory with no evidence of active exploitation at time of release.

Industry Insight

  • Organizations running Ivanti Neurons for ITSM on-premises should prioritize immediate patching, especially given the unauthenticated exploitability of two critical CVEs—delay increases exposure to remote code execution attacks.
  • The concentration of deserialization and authorization flaws in enterprise ITSM platforms highlights the ongoing risk in legacy software supply chains; vendors and customers should adopt continuous vulnerability monitoring and automated patch management.
  • With no known active exploitation reported, this represents a proactive security update window—teams should verify patch deployment across all supported versions before threat actors potentially weaponize the disclosed flaws.

TL;DR

  • Ivanti发布安全更新,修复Neurons for ITSM中8个安全漏洞,其中6个为严重级别,可导致远程代码执行
  • Sentry和EPMM产品分别修复了高严重性认证绕过漏洞(CVE-2026-83527和CVE-2026-18851)
  • 部分漏洞(CVE-2026-12744和CVE-2026-12745)可在无需认证的情况下被利用,CVSS评分高达9.9
  • Ivanti确认目前未发现这些漏洞在野外被利用的情况
  • Citrix同步修复了Workspace app的两个中等严重性漏洞

为什么值得看

本文对使用Ivanti ITSM、端点管理和移动设备管理产品的企业IT安全团队具有直接指导价值,帮助及时识别和修复关键安全风险。同时反映了当前IT基础设施软件持续面临的安全挑战趋势。

技术解析

  • Neurons for ITSM修复的漏洞主要包括两类:缺失授权问题(CVE-2026-12647/12645/12646,CVSS 9.9)和不可信数据反序列化弱点(CVE-2026-12650/12744/12745,CVSS 9.8-9.9),均可导致远程代码执行
  • Sentry版本R10.8.2/R10.7.3/R10.6.4修复的CVE-2026-83527为高严重性认证绕过漏洞,允许远程未认证攻击者获取管理员权限
  • EPMM版本12.10.0.0/12.9.0.2/12.8.0.4修复的CVE-2026-18851同样是认证绕过,但需要已认证用户才能利用
  • 所有漏洞已通过2026年9月安全更新修复,适用于Neurons for ITSM版本2025.2/2025.3/2025.4/2026.1,完整修复将在9月21日发布的2026.2版本中提供

行业启示

  • 企业IT服务管理(ITSM)和端点管理产品正成为攻击者重点目标,反序列化漏洞和认证绕过是主要利用向量,建议优先审查相关产品的安全配置
  • 关键基础设施软件供应商应建立更严格的安全开发生命周期(SDL),特别是在输入验证和反序列化数据处理方面加强防护
  • 建议企业建立自动化补丁管理流程,确保在供应商发布安全更新后能快速响应,降低漏洞利用窗口期风险

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Product Launch 产品发布