Missing Authorization in Ivanti Endpoint Manager Mobile Allows Admin Privilege Escalation
CVE-2026-18851 is a missing-authorization flaw (CWE-862) in Ivanti Endpoint Manager Mobile (EPMM) in which certain functionality fails to verify that an authenticated user is authorized to perform administrative actions. A remote attacker who already holds a valid low-privilege session can send crafted requests over the network, with no user interaction required, and escalate to administrator. From an admin position, the attacker gains full control of the mobile device management console, including access to managed-device data and the ability to alter or push configurations to enrolled devices. Organizations running EPMM versions before 12.10.0.0, 12.9.0.2, or 12.8.0.4 are affected. As of the advisory there is no known in-the-wild exploitation and no public proof-of-concept, it is not in CISA KEV (EPSS ~1.0%), and it was patched as part of a larger Ivanti batch covering EPMM, Neurons for ITSM and Sentry flaws enabling RCE and admin access.
· Ivanti Endpoint Manager Mobile (EPMM) All versions before 12.10.0.0, 12.9.0.2, and 12.8.0.4 (each supported release branch); fixed in 12.10.0.0, 12.9.0.2, and 12.8.0.4mass
Authentication Bypass in Ivanti Sentry Grants Remote Admin Access
CVE-2026-83527 is an authentication bypass (CWE-288) in Ivanti Sentry that allows a remote, unauthenticated attacker to gain administrative-level access to the appliance. It is triggered over the network with no prior privileges or user interaction, though the high-attack-complexity (AC:H) CVSS rating indicates exploitation depends on specific conditions rather than a trivially reliable path. A successful attacker obtains admin-level control of Sentry, the gateway component many organizations deploy alongside Ivanti EPMM/MobileIron for mobile device management, potentially exposing or disrupting device-management functions. Any organization running Ivanti Sentry on builds earlier than the fixed releases R10.8.2, R10.7.3, or R10.6.4 (depending on release line) is affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS assigns a 1.5% probability of exploitation within 30 days, so active exploitation is not currently confirmed.
· Ivanti Sentry All builds before R10.8.2, before R10.7.3, and before R10.6.4 (fixed in R10.8.2, R10.7.3, and R10.6.4, per release line)niche
Authenticated Deserialization RCE in Ivanti Neurons for ITSM
Ivanti Neurons for ITSM versions before 2026.2 contain a deserialization of untrusted data flaw (CWE-502) that allows remote code execution. A remote attacker who already holds valid (low-privilege) credentials sends crafted serialized data to the server, triggering the flaw; the CVSS scope-changed rating (9.9) indicates successful exploitation affects resources beyond the vulnerable component, effectively compromising the underlying server. An attacker gains arbitrary code execution on the ITSM server, with high impact on confidentiality, integrity, and availability. Any organization running an affected version of Ivanti Neurons for ITSM is exposed, though the authentication requirement means instances that are internet-facing or that expose accounts to partners/customers carry the highest risk. As of the data available, there is no evidence of in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA KEV; EPSS estimates roughly a 1.5% chance of exploitation within 30 days (72nd percentile).
· Ivanti Neurons for ITSM all versions before 2026.2moderate
Missing Authorization Flaw Enables Authenticated RCE in Ivanti Neurons for ITSM
CVE-2026-12645 is a critical Missing Authorization flaw (CWE-862) in Ivanti Neurons for ITSM, Ivanti's IT service management platform, where functionality on the server can be reached without the required authorization checks. A remote attacker who already holds valid low-privileged credentials can trigger the flaw with crafted requests to the affected component, and because the check is absent they can execute arbitrary code on the server. The CVSS scope-changed metric (S:C) indicates that successful exploitation may impact resources beyond the vulnerable component, with high impact to confidentiality, integrity, and availability. Organizations running Ivanti Neurons for ITSM in versions before 2026.2 are affected; the fix shipped as part of a batch of 10 patches across Ivanti's EPMM, Neurons for ITSM, and Sentry products. No exploitation in the wild, public proof-of-concept, or KEV listing is known, and EPSS currently estimates about a 1.2% probability of exploitation in the next 30 days.
· Ivanti Neurons for ITSM all versions before 2026.2large
Missing Authorization Enables Authenticated RCE in Ivanti Neurons for ITSM
CVE-2026-12646 is a missing authorization flaw (CWE-862) in Ivanti Neurons for ITSM in which privileged requests are not properly permission-checked. A remote attacker holding any valid low-privilege account can send crafted network requests that bypass the authorization check and execute arbitrary code on the server; the changed scope (S:C) in the CVSS score indicates compromise can extend beyond the vulnerable component itself. Successful exploitation has critical impact on confidentiality, integrity and availability (CVSS 3.1 9.9). Any organization running Neurons for ITSM on a release before 2026.2 is affected; the fix shipped in the 2026.2 release as part of a batch of ten Ivanti patches covering EPMM, Neurons for ITSM and Sentry. Exploitation status: no known in-the-wild exploitation, no public proof-of-concept, not listed in CISA KEV, and EPSS estimates roughly a 1.2% probability of exploitation within 30 days.
· Ivanti Neurons for ITSM all versions before 2026.2moderate
Authenticated RCE via Missing Authorization in Ivanti Neurons for ITSM
CVE-2026-12647 is a missing authorization flaw (CWE-862) in Ivanti Neurons for ITSM in versions before 2026.2, where certain requests are not properly checked against the user's permissions. A remote attacker who holds any authenticated, low-privileged account can send crafted requests that bypass the authorization check, with no user interaction required. The outcome is arbitrary code execution on the ITSM server, and the scope-changed CVSS rating indicates the impact extends beyond the vulnerable component, consistent with a full server compromise. Any organization running an affected Ivanti Neurons for ITSM deployment (on-premises or hosted) prior to 2026.2 is exposed. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at 1.2%, though it was patched alongside a batch of ten Ivanti flaws spanning EPMM, Neurons for ITSM and Sentry.
· Ivanti Neurons for ITSM all versions before 2026.2large
Unauthenticated RCE via Deserialization in Ivanti Neurons for ITSM
CVE-2026-12745 is a deserialization of untrusted data flaw (CWE-502) in Ivanti Neurons for ITSM, the vendor's enterprise IT service management platform. A remote, unauthenticated attacker can send crafted serialized data to a vulnerable instance over the network, which the server deserializes without validation. Successful exploitation results in arbitrary code execution on the server, with critical confidentiality, integrity, and availability impact (CVSS 3.1: 9.8). All deployments of Neurons for ITSM before version 2026.2 are affected, including instances published to the internet for self-service access. As of this analysis there is no known exploitation and no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 2.1% probability of exploitation within 30 days (81st percentile).
· Ivanti Neurons for ITSM all versions before 2026.2moderate
Unauthenticated Deserialization RCE in Ivanti Neurons for ITSM
CVE-2026-12744 is a deserialization of untrusted data flaw (CWE-502) in Ivanti Neurons for ITSM that allows a remote, unauthenticated attacker to execute arbitrary code on the server. It is triggered by sending crafted serialized input to the network-exposed ITSM service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms the attack requires no privileges, no user interaction, and low complexity. Successful exploitation yields full server compromise, with high impact to confidentiality, integrity, and availability. All organizations running Ivanti Neurons for ITSM on any release before 2026.2 are affected, with internet-exposed or broadly reachable deployments at greatest risk. There is no known public proof-of-concept, the flaw is not yet in CISA's KEV, and EPSS estimates a 2.2% probability of exploitation within 30 days, but the patch shipped as part of a recent batch of Ivanti fixes, so defenders should treat it as a priority despite the absence of confirmed exploitation.
· Ivanti Neurons for ITSM all versions before 2026.2moderate
Authenticated Deserialization RCE in Ivanti Neurons for ITSM
CVE-2026-12651 is a deserialization of untrusted data flaw (CWE-502) in Ivanti Neurons for ITSM that permits a remote, authenticated attacker to execute arbitrary code on the server. It is triggered by supplying crafted serialized data to the application over the network; only low-privilege valid credentials and no user interaction are required (CVSS 3.1: 8.8, AV:N/AC:L/PR:L/UI:N). Successful exploitation yields full code execution with high impact on confidentiality, integrity, and availability on the affected server. Any organization running Ivanti Neurons for ITSM on a version earlier than 2026.2 is affected. As of publication there are no known public proof-of-concepts, it is not in CISA KEV, and no confirmed in-the-wild exploitation is reported, though EPSS assigns a 1.5% probability of exploitation within 30 days, and the fix ships as part of a broader Ivanti batch patching 10 RCE and admin-access flaws across EPMM, Neurons for ITSM, and Sentry.
· Ivanti Neurons for ITSM all versions before 2026.2moderate
Authenticated Deserialization RCE in Ivanti Neurons for ITSM
Ivanti Neurons for ITSM versions before 2026.2 contain a deserialization of untrusted data flaw (CWE-502) that lets an attacker execute arbitrary code on the server. The flaw is triggered when the application deserializes attacker-controlled data, and it can be exploited remotely by any authenticated user with low-level privileges, without user interaction. Successful exploitation yields code execution with high impact on confidentiality, integrity and availability (CVSS 3.1: 8.8). Only organizations running vulnerable, self-hosted or on-prem instances of Ivanti Neurons for ITSM are affected; Ivanti's fixed release is 2026.2. Exploitation has not been observed in the wild, no public proof-of-concept is known, and the flaw is not yet in CISA's KEV catalog, with EPSS estimating a modest ~1.5% chance of exploitation in the next 30 days.
· Ivanti Neurons for ITSM all versions before 2026.2moderate