Search
Find merged stories by title or summary.
Ivanti security advisory (AV26-897)
Serial Number: AV26-897 Date: September 8, 2026 As of September 8, 2026, Ivanti is affected by vulnerabilities in the following products: • Endpoint Manager Mobile • Prior to 12.10.0.0 • Prior to 12.9.0.2 • Prior to 12.8.0.4 • Neurons for ITSM (Cloud/SaaS) • Prior to mo2026.2 • Neurons for ITSM On-Prem • Prior to 2025.2 Sept 2026 Security Patch • Prior to 2025.3 Sept 2026 Security Patch • Prior to 2025.4 Sept 2026 Security Patch • Prior to 2026.1 Sept 2026 Security Patch • Prior to 2026.2 • Sentry • Prior to R10.8.2 • Prior to R10.7.3 • Prior to R10.6.4 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacks
Ivanti has disclosed a wave of security advisories affecting three flagship enterprise products, Endpoint Manager Mobile , Neurons for ITSM, and Sentry, exposing organizations to risks ranging from privilege escalation to full remote code execution. The disclosures, published on September 8, 2026, cover ten distinct CVEs, several rated critical, underscoring the breadth of exposure across Ivanti’s mobile device management and IT service management ecosystem. Ivanti EPMM Vulnerabilities The first advisory addresses CVE-2026-18851, a high-severity missing authorization flaw in Ivanti Endpoint Manager Mobile (EPMM) carrying a CVSS score of 8.8. The vulnerability, rooted in CWE-862, allows a remote authenticated attacker to escalate privileges to full administrator access. Versions 12. 9. 0. 1 and earlier, 12. 8. 0. 3 and earlier, and all builds prior to 12. 10. 0. 0 are affected.
Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter
A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs.
Ivanti EPM Update Patches Remotely Exploitable Flaws
The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek .
Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases. The hole is in Windows’ Ancillary Function Driver for WinSock ( CVE-2026-68820 ), which, according to Todd Schell , principal product manager at Ivanti, has been a recurring target for local privilege-escalation bugs throughout 2026. Past vulnerabilities in this component have let an authorized attacker win a race condition to gain SYSTEM privileges. “Exploitation has already been detected,” noted Jack Bicer , director of vulnerability research at Action1, “making this the highest priority vulnerability in this month’s release.” Separately, SAP issued 29 new and updated security patches, the most severe of which is CVE-2026-58231 , with a CVSS score of 10.
Ivanti security advisory (AV26-805)
Serial Number: AV26-805 Date: August 11, 2026 As of August 11, 2026, Ivanti is affected by vulnerabilities in the following product: • Endpoint Manager • Prior to or equal to 2024 SU6 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. • Ivanti Innovators Hub Ivanti security advisory (AV26-805) - Canadian Centre for Cyber Security
Ivanti Endpoint Manager Vulnerabilities Let Remote Attackers Crash Agent Service
Ivanti has issued a security advisory for Ivanti Endpoint Manager (EPM), disclosing three high-severity vulnerabilities that could allow remote attackers to crash agent services, hijack cloud storage configurations, and intercept sensitive database credentials. Published on August 11, 2026, the advisory impacts all EPM 2024 SU6 and earlier deployments, urging security teams to update to the newly released 2024 SU7 build without delay. Ivanti Endpoint Manager Vulnerabilities The disclosed flaws span agent components, core management services, and external integrations: Tracked as CVE-2026-18125, this out-of-bounds read vulnerability in the EPM Agent carries a CVSS score of 7.5. It enables a remote, unauthenticated attacker to crash the agent service on managed endpoints by sending crafted input, requiring no user interaction or valid credentials.
Deadline-driven defense.
CISA directs agencies to “patch smarter, not harder.” The House fails to extend FISA. Europol pulls over AudiA6. GitHub announces npm security updates. Anthropic rejects Fable 5 jailbreak claims. CISA gives feds three days to patch a critical Ivanti Sentry vulnerability. Google confirms ShinyHunters exploited a critical Oracle PeopleSoft vulnerability. FancyBear shifts part of its infrastructure to compromised edge devices. Pundits push for CyberCorps scholarship budgets. Our guest is Dr. Renée Burton, VP of Threat Intelligence at Infoblox, to discuss scams targeting the World Cup. Amazon drivers sweat through a software update. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing , and you’ll never miss a beat . And be sure to follow CyberWire Daily on LinkedIn .
The court calls Google’s bluff.
Google faces liability for AI-generated claims. Washington pauses public AI model assessments. Anthropic ships a safer AI model. OpenAI disrupts influence operations. Ransomware operators get a powerful new backdoor. Urgent patches land for Ivanti and Veeam. PyPI supply chain attacks evolve. And a massive data breach triggers a record fine in South Korea. Our guest is Peter Barker, Chief Product Officer at Ping Identity, sharing how identity increasingly becomes the control plane for how work gets done. AI analyzes the FIFA World cup, one cliché at a time. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing , and you’ll never miss a beat . And be sure to follow CyberWire Daily on LinkedIn .
The four-day race you don’t want to be in.
CISA orders rapid patching of actively exploited Ivanti zero-day. Canvas gets hacked during finals week. Dirty Frag is a new Linux zero-day. Researchers document a serious Claude Chrome extension bug. Meta ends Instagram encryption. PCPJack malware clean house before moving in. A new report highlights quantum-era cryptographic threats. Cloudflare announces layoffs amidst AI deployment. Sri Lankan police shut down a scam center. Maria Varmazis joins me to look back at ten years of geopolitics in cyber. Vibe coding reveals valuable data. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
Hackers ignore the ceasefire.
Iran-linked hackers signal cyberattacks will continue despite the cease-fire. Microsoft restores access after suspending open-source developer accounts. John Deere settles its right-to-repair fight. A suspected Adobe Reader zero-day surfaces. Palo Alto Networks and SonicWall patch high-severity flaws. New macOS malware targets crypto wallets. A threat cluster abuses live chat to bypass MFA. CISA orders urgent Ivanti patching. Researchers track a stealthy DDoS-for-hire botnet. Our guest is Edgard Capdevielle, CEO of Nozomi Networks, sharing insights on threats posed by nation-states and AI on OT security. macOS has a 49 day time limit. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing , and you’ll never miss a beat . And be sure to follow CyberWire Daily on LinkedIn .
Issue 231: API authentication bypass in Ivanti Sentry, Docker images expose API and keys
This week, we have news of an API authentication bypass vulnerability in the Ivanti Sentry cybersecurity product and a report into Docker images that are exposing APIs and private keys. We also have articles on API security’s role in protecting retail apps, how APIs and generative AI interoperate, and how attackers bypass Web Application Firewalls. We conclude with Dana Epp showing how to use Postman Flows for exploiting APIs. Vulnerability: API authentication bypass in Ivanti Sentry First up this week is news of a vulnerability in the Ivanti Sentry cybersecurity product. The vulnerability (tracked as CVE-2023-38035 ) impacts versions 9. 18 and earlier of the product. The vulnerability allows an attacker to access an administration API endpoint (running on port 8443 by default) without any authentication at all.
You've reached the end of current stories for this search.
