Ivanti security advisory (AV26-897)
Canada's Cyber Centre relayed Ivanti's September 2026 security updates for Endpoint Manager Mobile, Neurons for ITSM, and Sentry, urging administrators to patch.
The Canadian Centre for Cyber Security forwarded Ivanti's September 2026 security updates covering Endpoint Manager Mobile, Neurons for ITSM (cloud/SaaS and on-prem), and Sentry. Affected releases include Endpoint Manager Mobile prior to 12.10.0.0, Sentry prior to R10.8.2, and Neurons for ITSM on-prem prior to 2026.2. The advisory references CVE-2026-18851 for Endpoint Manager Mobile and CVE-2026-83527 for Sentry, plus multiple CVEs in Neurons for ITSM. No exploitation is described in the advisory text.
- Updates address Ivanti Endpoint Manager Mobile (CVE-2026-18851) and Sentry (CVE-2026-83527).
- Neurons for ITSM cloud and on-prem received fixes in the September 2026 update.
- Administrators are urged to review the advisories and apply updates as available.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-18851 | Missing Authorization in Ivanti Endpoint Manager Mobile Allows Admin Privilege Escalation CVE-2026-18851 is a missing-authorization flaw (CWE-862) in Ivanti Endpoint Manager Mobile (EPMM) in which certain functionality fails to verify that an authenticated user is authorized to perform administrative actions. A remote attacker who already holds a valid low-privilege session can send crafted requests over the network, with no user interaction required, and escalate to administrator. From an admin position, the attacker gains full control of the mobile device management console, including access to managed-device data and the ability to alter or push configurations to enrolled devices. Organizations running EPMM versions before 12.10.0.0, 12.9.0.2, or 12.8.0.4 are affected. As of the advisory there is no known in-the-wild exploitation and no public proof-of-concept, it is not in CISA KEV (EPSS ~1.0%), and it was patched as part of a larger Ivanti batch covering EPMM, Neurons for ITSM and Sentry flaws enabling RCE and admin access. Do: Upgrade EPMM to 12.10.0.0, 12.9.0.2, or 12.8.0.4 depending on the release branch in use, per Ivanti's advisory. Until patched, restrict EPMM console/API interfaces to trusted networks and review logs for authenticated users performing unexpected administrative actions. Because this fix ships in the same batch as other EPMM, Neurons for ITSM and Sentry patches, apply the full set of vendor updates rather than only this CVE. | 8.8 | 1% |
| massplausibly >1,000,000 managed devices/users across tens of thousands of enterprise and government deployments | ||
| CVE-2026-83527 | Authentication Bypass in Ivanti Sentry Grants Remote Admin Access CVE-2026-83527 is an authentication bypass (CWE-288) in Ivanti Sentry that allows a remote, unauthenticated attacker to gain administrative-level access to the appliance. It is triggered over the network with no prior privileges or user interaction, though the high-attack-complexity (AC:H) CVSS rating indicates exploitation depends on specific conditions rather than a trivially reliable path. A successful attacker obtains admin-level control of Sentry, the gateway component many organizations deploy alongside Ivanti EPMM/MobileIron for mobile device management, potentially exposing or disrupting device-management functions. Any organization running Ivanti Sentry on builds earlier than the fixed releases R10.8.2, R10.7.3, or R10.6.4 (depending on release line) is affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS assigns a 1.5% probability of exploitation within 30 days, so active exploitation is not currently confirmed. Do: Upgrade Ivanti Sentry to R10.8.2 (or R10.7.3 / R10.6.4 for the corresponding release line) as addressed in Ivanti's advisory AV26-897. Until patched, minimize Sentry's internet exposure to required management/enrollment traffic and review appliance logs for unexpected administrator logins. Ivanti EPMM and Neurons for ITSM administrators should also review the same advisory, which covers additional flaws in those products. | 8.1 | 1% |
| nichelikely low-thousands of deployments, with only a few hundred internet-exposed instances in past public scans |
Full article132 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-897
Date: September 8, 2026
As of September 8, 2026, Ivanti is affected by vulnerabilities in the following products:
- Endpoint Manager Mobile
- Prior to 12.10.0.0
- Prior to 12.9.0.2
- Prior to 12.8.0.4
- Neurons for ITSM (Cloud/SaaS)
- Prior to mo2026.2
- Neurons for ITSM On-Prem
- Prior to 2025.2 Sept 2026 Security Patch
- Prior to 2025.3 Sept 2026 Security Patch
- Prior to 2025.4 Sept 2026 Security Patch
- Prior to 2026.1 Sept 2026 Security Patch
- Prior to 2026.2
- Sentry
- Prior to R10.8.2
- Prior to R10.7.3
- Prior to R10.6.4
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/ivanti-security-advisory-av26-897