Ivanti Fixes Critical Security Holes in Three Business Software Products
Six flaws in Ivanti Neurons for ITSM could let attackers run malicious code on affected systems from anywhere on the internet. Two other products, Sentry and EPMM, received fixes for authentication bypass bugs.

Key points
- Ivanti patched six critical-rated vulnerabilities in its Neurons for ITSM product, all of which could allow remote code execution.
- Two additional products, Ivanti Sentry and Ivanti EPMM, received patches for authentication bypass flaws.
- Remote code execution flaws are among the most serious type: attackers can run their own software on a victim's systems without needing physical access.
- No patch covers every user automatically; organisations running affected versions must apply updates manually.
Ivanti, a company that sells software used by IT departments to manage devices and handle internal support tickets, has released security updates for three of its products after researchers found serious vulnerabilities, meaning weaknesses in the code that attackers could exploit.
What did the attackers find?
The most serious problems sit inside Ivanti Neurons for ITSM, a help-desk and IT service management platform used to log and track employee support requests. Six separate vulnerabilities carry a "critical" severity rating, and each one could allow remote code execution, which means an attacker anywhere on the internet could send specially crafted requests to the software and cause it to run malicious code of their choosing, without needing a password or physical access to the building.
That is a worst-case scenario for any software flaw.
Ivanti Sentry and Ivanti EPMM (Enterprise Point-of-Need Mobility Management, software companies use to manage smartphones and laptops issued to staff) both received patches for authentication bypass vulnerabilities. An authentication bypass lets an attacker skip the login step entirely, reaching parts of a system that should require a valid username and password.
Should the people who use these products be worried?
If your employer uses any of these three Ivanti products and has not yet applied the patches, yes. The risk is real.
Organisations relying on unpatched versions of Neurons for ITSM, Sentry, or EPMM should treat this as urgent. Ivanti's advisory pages contain the exact version numbers that are safe; IT teams should compare those against whatever is currently running.
Firstreported by SecurityWeek, details on the specific CVE identifiers (the official reference numbers assigned to each named vulnerability) and the patched version numbers had not been fully enumerated in early coverage, so affected customers should consult Ivanti's security advisory portal directly for the authoritative list.
What should ordinary employees do?
Most staff will not touch these systems directly. IT administrators are the ones who need to act fast.
If you are an employee at a company that uses Ivanti products, the practical step is simple: flag this article to your IT or security team and ask whether the patches have been applied. You do not need to do anything technical yourself.
Common questions
Is my personal data at risk?
Potentially, if your employer uses the affected software and has not patched it. Help-desk platforms often hold staff names, email addresses, and device details. A successful attack could expose that information.
How long do companies usually have before attackers start exploiting flaws like this?
Historically, attackers begin probing newly disclosed vulnerabilities within days of a public announcement. Ivanti products have been targeted in the past, which makes prompt patching especially important here.



