CVE-2025-22462: Ivanti Neurons For Itsm

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system.

Affected products

  • Ivanti Neurons For Itsm: before 2023.4 (fixed in 2023.4); version 2023.4 only; version 2024.2 only; version 2024.3 only

Published 2025-05-13. Last modified 2026-06-17.