AI analysis
Ivanti Neurons for ITSM versions before 2026.2 contain a deserialization of untrusted data flaw (CWE-502) that allows remote code execution. A remote attacker who already holds valid (low-privilege) credentials sends crafted serialized data to the server, triggering the flaw; the CVSS scope-changed rating (9.9) indicates successful exploitation affects resources beyond the vulnerable component, effectively compromising the underlying server. An attacker gains arbitrary code execution on the ITSM server, with high impact on confidentiality, integrity, and availability. Any organization running an affected version of Ivanti Neurons for ITSM is exposed, though the authentication requirement means instances that are internet-facing or that expose accounts to partners/customers carry the highest risk. As of the data available, there is no evidence of in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA KEV; EPSS estimates roughly a 1.5% chance of exploitation within 30 days (72nd percentile).
What to do: Upgrade Ivanti Neurons for ITSM to version 2026.2 or later, and apply Ivanti's current patch bundle covering the related EPMM, Neurons, and Sentry flaws. Until patched, review whether the ITSM instance is internet-exposed, audit and restrict which accounts can reach it (disable stale or partner-facing credentials), and monitor Ivanti advisories for news of active exploitation since exploitation requires valid authentication.
Affected
| Ivanti Neurons for ITSM | all versions before 2026.2 |
Estimated exposure
moderateon the order of thousands of deployments (one server or cloud tenant per customer); no public install counts — Ivanti Neurons for ITSM (formerly Ivanti Service Manager/HEAT) is an enterprise ITSM platform used by thousands of organizations, each typically running a single server or cloud tenant, implying an affected population in the low thousands…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.