AI analysis
CVE-2026-12744 is a deserialization of untrusted data flaw (CWE-502) in Ivanti Neurons for ITSM that allows a remote, unauthenticated attacker to execute arbitrary code on the server. It is triggered by sending crafted serialized input to the network-exposed ITSM service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms the attack requires no privileges, no user interaction, and low complexity. Successful exploitation yields full server compromise, with high impact to confidentiality, integrity, and availability. All organizations running Ivanti Neurons for ITSM on any release before 2026.2 are affected, with internet-exposed or broadly reachable deployments at greatest risk. There is no known public proof-of-concept, the flaw is not yet in CISA's KEV, and EPSS estimates a 2.2% probability of exploitation within 30 days, but the patch shipped as part of a recent batch of Ivanti fixes, so defenders should treat it as a priority despite the absence of confirmed exploitation.
What to do: Upgrade Ivanti Neurons for ITSM to version 2026.2 or later. Until patched, restrict network access to the ITSM server to trusted ranges (e.g., internal-only firewall rules or VPN), since unauthenticated attackers on any reachable network path can attempt exploitation. Because this fix was released alongside a batch of Ivanti patches covering EPMM, Neurons, and Sentry, review and apply the full advisory set rather than this CVE alone.
Affected
| Ivanti Neurons for ITSM | all versions before 2026.2 |
Estimated exposure
moderate~1,000-10,000 server instances/tenants (exact install base unknown) — No public installation counts exist; the estimate reflects that Ivanti Neurons for ITSM is an enterprise ITSM suite typically deployed as one server instance or cloud tenant per organization, implying a worldwide installed base in the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.