Ivanti Patches Critical RCE in Neurons, EPMM, Sentry
Ivanti's September 2026 patches close six critical RCEs in Neurons for ITSM and authentication bypass flaws in Sentry and EPMM. Patch now.

Ivanti released security patches this week covering three of its enterprise management platforms: Neurons for ITSM, Ivanti Sentry, and Enterprise Platform Mobile Management (EPMM). The patches close six critical vulnerabilities in Neurons for ITSM, each capable of enabling remote code execution, along with authentication bypass flaws in Sentry and EPMM. CVE IDs and version-specific details are in Ivanti’s security advisories page.
Neurons for ITSM
Neurons for ITSM is Ivanti’s IT service management platform: organizations use it to handle ticketing, asset management, and service workflows. Six of this batch’s vulnerabilities land there, all rated critical, all involving remote code execution. The exact attack surfaces vary by CVE, but critical-severity RCE in a web-facing service management tool is a straightforward priority-one patch for any org running it.
ITSM platforms are reasonably high-value targets in post-intrusion scenarios. They sit on your internal network, they hold asset inventories, they have broad query access to configuration data, and they often authenticate with elevated service accounts. A remote code execution path into one is a foothold with substantial lateral reach, not just a standalone compromise.
Sentry and EPMM
Ivanti Sentry is the on-premises gateway that sits in front of mobile device traffic, proxying email and application access before it reaches backend Exchange or other services. The authentication bypass in this batch means an unauthenticated attacker could reach functionality that is supposed to require credentials. The attack surface depends on whether Sentry is exposed directly to the internet or behind a VPN, but in the common deployment model it carries external-facing exposure.
EPMM is Ivanti’s mobile device management product. Authentication bypass flaws in MDM platforms carry similar logic: once an attacker can call authenticated API endpoints without credentials, they can query enrolled devices, push configurations, or access policies. The specific scope of what is accessible without authentication in this particular EPMM flaw is in the advisory.
What to do
Patch. Ivanti’s security advisories list the fixed versions for each product. Apply the current supported release, check that your Neurons for ITSM, Sentry, and EPMM installations are on it, and verify. The advisory process for all three followed Ivanti’s standard coordinated disclosure; no confirmed in-the-wild exploitation of this batch has been reported as of this writing, though that gap tends to close faster on Ivanti products than the vendor prefers.
Ivanti has had high-profile exploit activity against its VPN and Connect Secure products over the past year. See the Inside Ivanti Connect Secure’s Chained Zero-Days write-up for the broader pattern. The current batch is a separate product line, but the pattern of researchers and threat actors prioritizing Ivanti advisory disclosures for rapid exploitation testing is well-established. Treat “no known exploitation yet” as a window that closes, not a reassurance.
This week’s patch wave also included Microsoft’s record-breaking September Patch Tuesday across 974 vulnerabilities, including two exploited zero-days. If your patch cycle is backed up, triage accordingly: actively exploited CVEs first, critical remote code execution with external exposure second, authentication bypasses in internally-exposed services third.
Found this useful? Share it.
