ZeroHour

CVE-2026-12651

moderate

Authenticated Deserialization RCE in Ivanti Neurons for ITSM

CVSS 3.1
8.8 high
EPSS
1%p72
Published
()
Modified
AI analysis

CVE-2026-12651 is a deserialization of untrusted data flaw (CWE-502) in Ivanti Neurons for ITSM that permits a remote, authenticated attacker to execute arbitrary code on the server. It is triggered by supplying crafted serialized data to the application over the network; only low-privilege valid credentials and no user interaction are required (CVSS 3.1: 8.8, AV:N/AC:L/PR:L/UI:N). Successful exploitation yields full code execution with high impact on confidentiality, integrity, and availability on the affected server. Any organization running Ivanti Neurons for ITSM on a version earlier than 2026.2 is affected. As of publication there are no known public proof-of-concepts, it is not in CISA KEV, and no confirmed in-the-wild exploitation is reported, though EPSS assigns a 1.5% probability of exploitation within 30 days, and the fix ships as part of a broader Ivanti batch patching 10 RCE and admin-access flaws across EPMM, Neurons for ITSM, and Sentry.

What to do: Upgrade Ivanti Neurons for ITSM to 2026.2 or later per Ivanti's advisory, which also covers related EPMM, Neurons, and Sentry flaws. Until patched, restrict network access to the ITSM application (VPN or allow-listing) and review which low-privilege user accounts exist, since valid credentials are required for exploitation. Monitor the application server for unexpected process spawns or outbound connections consistent with deserialization-based code execution.

Affected
Ivanti Neurons for ITSMall versions before 2026.2
Estimated exposure
moderateon the order of a few thousand enterprise deployments, with only a subset internet-exposed — Ivanti Neurons for ITSM (formerly HEAT/Service Manager) is enterprise ITSM software deployed per customer organization as a hosted tenant or on-premises server, so the installed base plausibly sits in the low thousands rather than hundreds…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacks

Ivanti patched ten CVEs across EPMM, Neurons for ITSM and Sentry, including critical unauthenticated deserialization RCE; no active exploitation reported.

On September 8, 2026, Ivanti disclosed advisories covering ten CVEs in Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry. The most severe are two unauthenticated deserialization RCE flaws in Neurons for ITSM, CVE-2026-12744 and CVE-2026-12745 (CVSS 9.8), plus three missing-authorization RCE bugs rated 9.9 and three authenticated deserialization RCE flaws. EPMM has CVE-2026-18851 (CVSS 8.8), an authenticated privilege escalation flaw, and Sentry has CVE-2026-83527 (CVSS 8.1), an authentication bypass. Ivanti reports no evidence of active exploitation; cloud/SaaS ITSM was patched on August 9, 2026, while on-premises 2025.2 through 2026.1 require September 2026 patches.

Ivanti Patches Critical Flaws Across Enterprise Security Products

Ivanti released September updates fixing six critical RCE flaws in Neurons for ITSM plus authentication bypasses in Sentry and EPMM; no exploitation seen.

Ivanti's September 2026 updates fix eight flaws in Neurons for ITSM, six of them critical remote code execution bugs with CVSS scores up to 9.9, including missing authorization issues (CVE-2026-12647, CVE-2026-12645, CVE-2026-12646) and deserialization flaws (CVE-2026-12650, CVE-2026-12744, CVE-2026-12745). Sentry releases R10.8.2, R10.7.3, and R10.6.4 patch CVE-2026-83527, an unauthenticated high-severity authentication bypass, while EPMM versions 12.10.0.0, 12.9.0.2, and 12.8.0.4 fix the authenticated bypass CVE-2026-18851. Ivanti says it is not aware of any exploitation in the wild. Citrix separately patched two medium-severity flaws in Workspace app for Windows.

Ivanti Patches 10 EPMM, Neurons for ITSM and Sentry Flaws Enabling RCE and Admin Access

Ivanti patches 10 flaws in EPMM, Neurons for ITSM, and Sentry, including two 9.8-rated unauthenticated RCEs in ITSM.

Ivanti released fixes for 10 vulnerabilities across Endpoint Manager Mobile, Neurons for ITSM, and Sentry, and said it was not aware of active exploitation at disclosure. The most severe are CVE-2026-12744 and CVE-2026-12745, unauthenticated deserialization RCEs rated 9.8 in Neurons for ITSM, alongside authenticated deserialization and missing-authorization RCEs rated up to 9.9. CVE-2026-18851 is an 8.8-rated EPMM privilege escalation to administrator, and CVE-2026-83527 is an 8.1-rated unauthenticated authentication bypass in Sentry granting administrative access. Ivanti said the ITSM weaknesses were found using large language models; Cloud/SaaS fixes shipped August 9, 2026, and on-premises patches are available from September 2026.