AI analysis
CVE-2026-12651 is a deserialization of untrusted data flaw (CWE-502) in Ivanti Neurons for ITSM that permits a remote, authenticated attacker to execute arbitrary code on the server. It is triggered by supplying crafted serialized data to the application over the network; only low-privilege valid credentials and no user interaction are required (CVSS 3.1: 8.8, AV:N/AC:L/PR:L/UI:N). Successful exploitation yields full code execution with high impact on confidentiality, integrity, and availability on the affected server. Any organization running Ivanti Neurons for ITSM on a version earlier than 2026.2 is affected. As of publication there are no known public proof-of-concepts, it is not in CISA KEV, and no confirmed in-the-wild exploitation is reported, though EPSS assigns a 1.5% probability of exploitation within 30 days, and the fix ships as part of a broader Ivanti batch patching 10 RCE and admin-access flaws across EPMM, Neurons for ITSM, and Sentry.
What to do: Upgrade Ivanti Neurons for ITSM to 2026.2 or later per Ivanti's advisory, which also covers related EPMM, Neurons, and Sentry flaws. Until patched, restrict network access to the ITSM application (VPN or allow-listing) and review which low-privilege user accounts exist, since valid credentials are required for exploitation. Monitor the application server for unexpected process spawns or outbound connections consistent with deserialization-based code execution.
Affected
| Ivanti Neurons for ITSM | all versions before 2026.2 |
Estimated exposure
moderateon the order of a few thousand enterprise deployments, with only a subset internet-exposed — Ivanti Neurons for ITSM (formerly HEAT/Service Manager) is enterprise ITSM software deployed per customer organization as a hosted tenant or on-premises server, so the installed base plausibly sits in the low thousands rather than hundreds…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.