ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire1

Ivanti Patches Critical Flaws Across Enterprise Security Products

AI summary · glm-5.3-flash

Ivanti released September updates fixing six critical RCE flaws in Neurons for ITSM plus authentication bypasses in Sentry and EPMM; no exploitation seen.

Ivanti's September 2026 updates fix eight flaws in Neurons for ITSM, six of them critical remote code execution bugs with CVSS scores up to 9.9, including missing authorization issues (CVE-2026-12647, CVE-2026-12645, CVE-2026-12646) and deserialization flaws (CVE-2026-12650, CVE-2026-12744, CVE-2026-12745). Sentry releases R10.8.2, R10.7.3, and R10.6.4 patch CVE-2026-83527, an unauthenticated high-severity authentication bypass, while EPMM versions 12.10.0.0, 12.9.0.2, and 12.8.0.4 fix the authenticated bypass CVE-2026-18851. Ivanti says it is not aware of any exploitation in the wild. Citrix separately patched two medium-severity flaws in Workspace app for Windows.

  • Neurons for ITSM received fixes for eight flaws, six critical RCE bugs with CVSS up to 9.9.
  • Only CVE-2026-12744 and CVE-2026-12745 are exploitable without authentication.
  • Sentry patches CVE-2026-83527 and EPMM patches CVE-2026-18851, both authentication bypasses.
  • Ivanti says none of the vulnerabilities have been exploited in the wild.
  • Fixes shipped in September 2026 updates for ITSM versions 2025.2 through 2026.1.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-12645
+2 in the same advisory: …12646 …12647
Missing Authorization Flaw Enables Authenticated RCE in Ivanti Neurons for ITSM

CVE-2026-12645 is a critical Missing Authorization flaw (CWE-862) in Ivanti Neurons for ITSM, Ivanti's IT service management platform, where functionality on the server can be reached without the required authorization checks. A remote attacker who already holds valid low-privileged credentials can trigger the flaw with crafted requests to the affected component, and because the check is absent they can execute arbitrary code on the server. The CVSS scope-changed metric (S:C) indicates that successful exploitation may impact resources beyond the vulnerable component, with high impact to confidentiality, integrity, and availability. Organizations running Ivanti Neurons for ITSM in versions before 2026.2 are affected; the fix shipped as part of a batch of 10 patches across Ivanti's EPMM, Neurons for ITSM, and Sentry products. No exploitation in the wild, public proof-of-concept, or KEV listing is known, and EPSS currently estimates about a 1.2% probability of exploitation in the next 30 days.

Do: Upgrade Ivanti Neurons for ITSM to version 2026.2 or later per Ivanti's advisory. Until patched, restrict which accounts can reach the platform, watch for anomalous authenticated activity and unexpected server-side code execution, and check Ivanti's advisory for any interim mitigation or workaround guidance. Because exploitation requires valid credentials, also review accounts with low-privileged access to the ITSM instance for signs of compromise.

9.91%
  • Ivanti Neurons for ITSM all versions before 2026.2
largeroughly 1,000-10,000 enterprise deployments/tenants, with aggregate internal users plausibly in the hundreds of thousands (exact counts not publicly published)
CVE-2026-12650
+2 in the same advisory: …12648 …12651
Authenticated Deserialization RCE in Ivanti Neurons for ITSM

Ivanti Neurons for ITSM versions before 2026.2 contain a deserialization of untrusted data flaw (CWE-502) that allows remote code execution. A remote attacker who already holds valid (low-privilege) credentials sends crafted serialized data to the server, triggering the flaw; the CVSS scope-changed rating (9.9) indicates successful exploitation affects resources beyond the vulnerable component, effectively compromising the underlying server. An attacker gains arbitrary code execution on the ITSM server, with high impact on confidentiality, integrity, and availability. Any organization running an affected version of Ivanti Neurons for ITSM is exposed, though the authentication requirement means instances that are internet-facing or that expose accounts to partners/customers carry the highest risk. As of the data available, there is no evidence of in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA KEV; EPSS estimates roughly a 1.5% chance of exploitation within 30 days (72nd percentile).

Do: Upgrade Ivanti Neurons for ITSM to version 2026.2 or later, and apply Ivanti's current patch bundle covering the related EPMM, Neurons, and Sentry flaws. Until patched, review whether the ITSM instance is internet-exposed, audit and restrict which accounts can reach it (disable stale or partner-facing credentials), and monitor Ivanti advisories for news of active exploitation since exploitation requires valid authentication.

9.9
group max
1%
  • Ivanti Neurons for ITSM all versions before 2026.2
moderateon the order of thousands of deployments (one server or cloud tenant per customer); no public install counts
CVE-2026-12744
+1 in the same advisory: …12745
Unauthenticated Deserialization RCE in Ivanti Neurons for ITSM

CVE-2026-12744 is a deserialization of untrusted data flaw (CWE-502) in Ivanti Neurons for ITSM that allows a remote, unauthenticated attacker to execute arbitrary code on the server. It is triggered by sending crafted serialized input to the network-exposed ITSM service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms the attack requires no privileges, no user interaction, and low complexity. Successful exploitation yields full server compromise, with high impact to confidentiality, integrity, and availability. All organizations running Ivanti Neurons for ITSM on any release before 2026.2 are affected, with internet-exposed or broadly reachable deployments at greatest risk. There is no known public proof-of-concept, the flaw is not yet in CISA's KEV, and EPSS estimates a 2.2% probability of exploitation within 30 days, but the patch shipped as part of a recent batch of Ivanti fixes, so defenders should treat it as a priority despite the absence of confirmed exploitation.

Do: Upgrade Ivanti Neurons for ITSM to version 2026.2 or later. Until patched, restrict network access to the ITSM server to trusted ranges (e.g., internal-only firewall rules or VPN), since unauthenticated attackers on any reachable network path can attempt exploitation. Because this fix was released alongside a batch of Ivanti patches covering EPMM, Neurons, and Sentry, review and apply the full advisory set rather than this CVE alone.

9.82%
  • Ivanti Neurons for ITSM all versions before 2026.2
moderate~1,000-10,000 server instances/tenants (exact install base unknown)
CVE-2026-18851
Missing Authorization in Ivanti Endpoint Manager Mobile Allows Admin Privilege Escalation

CVE-2026-18851 is a missing-authorization flaw (CWE-862) in Ivanti Endpoint Manager Mobile (EPMM) in which certain functionality fails to verify that an authenticated user is authorized to perform administrative actions. A remote attacker who already holds a valid low-privilege session can send crafted requests over the network, with no user interaction required, and escalate to administrator. From an admin position, the attacker gains full control of the mobile device management console, including access to managed-device data and the ability to alter or push configurations to enrolled devices. Organizations running EPMM versions before 12.10.0.0, 12.9.0.2, or 12.8.0.4 are affected. As of the advisory there is no known in-the-wild exploitation and no public proof-of-concept, it is not in CISA KEV (EPSS ~1.0%), and it was patched as part of a larger Ivanti batch covering EPMM, Neurons for ITSM and Sentry flaws enabling RCE and admin access.

Do: Upgrade EPMM to 12.10.0.0, 12.9.0.2, or 12.8.0.4 depending on the release branch in use, per Ivanti's advisory. Until patched, restrict EPMM console/API interfaces to trusted networks and review logs for authenticated users performing unexpected administrative actions. Because this fix ships in the same batch as other EPMM, Neurons for ITSM and Sentry patches, apply the full set of vendor updates rather than only this CVE.

8.81%
  • Ivanti Endpoint Manager Mobile (EPMM) All versions before 12.10.0.0, 12.9.0.2, and 12.8.0.4 (each supported release branch); fixed in 12.10.0.0, 12.9.0.2, and 12.8.0.4
massplausibly >1,000,000 managed devices/users across tens of thousands of enterprise and government deployments
CVE-2026-83527
Authentication Bypass in Ivanti Sentry Grants Remote Admin Access

CVE-2026-83527 is an authentication bypass (CWE-288) in Ivanti Sentry that allows a remote, unauthenticated attacker to gain administrative-level access to the appliance. It is triggered over the network with no prior privileges or user interaction, though the high-attack-complexity (AC:H) CVSS rating indicates exploitation depends on specific conditions rather than a trivially reliable path. A successful attacker obtains admin-level control of Sentry, the gateway component many organizations deploy alongside Ivanti EPMM/MobileIron for mobile device management, potentially exposing or disrupting device-management functions. Any organization running Ivanti Sentry on builds earlier than the fixed releases R10.8.2, R10.7.3, or R10.6.4 (depending on release line) is affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS assigns a 1.5% probability of exploitation within 30 days, so active exploitation is not currently confirmed.

Do: Upgrade Ivanti Sentry to R10.8.2 (or R10.7.3 / R10.6.4 for the corresponding release line) as addressed in Ivanti's advisory AV26-897. Until patched, minimize Sentry's internet exposure to required management/enrollment traffic and review appliance logs for unexpected administrator logins. Ivanti EPMM and Neurons for ITSM administrators should also review the same advisory, which covers additional flaws in those products.

8.11%
  • Ivanti Sentry All builds before R10.8.2, before R10.7.3, and before R10.6.4 (fixed in R10.8.2, R10.7.3, and R10.6.4, per release line)
nichelikely low-thousands of deployments, with only a few hundred internet-exposed instances in past public scans
Full article345 words · extracted from securityweek.com · click to collapse

Ivanti on Tuesday announced security updates that address vulnerabilities rated critical and high severity in its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) products.

Neurons for ITSM received fixes for the largest number of security defects. Of the eight bugs, six are critical-severity issues that could lead to remote code execution, Ivanti warns.

These include CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646 (CVSS score of 9.9/10), described as missing authorization issues; and CVE-2026-12650 (CVSS score of 9.9/10), CVE-2026-12744, and CVE-2026-12745 (CVSS score of 9.8/10), described as deserialization of untrusted data weaknesses.

The remaining two bugs, tracked as CVE-2026-12651 and CVE-2026-12648, are high-severity deserialization of untrusted data defects also leading to remote code execution.

According to Ivanti’s advisory, only CVE-2026-12744 and CVE-2026-12745 can be exploited without authentication.

All vulnerabilities were addressed with the September 2026 security updates rolled out for Neurons for ITSM versions 2025.2, 2025.3, 2025.4, and 2026.1. The fixes will also be included in version 2026.2 of the product, scheduled for September 21.

Advertisement. Scroll to continue reading.

“Customers using the on-premises version of Ivanti Neurons for ITSM should update their solution to one of the resolved versions to address the vulnerabilities,” Ivanti notes.

On Tuesday, Ivanti released Sentry versions R10.8.2, R10.7.3, and R10.6.4 with patches for CVE-2026-83527, a high-severity authentication bypass that could allow remote, unauthenticated attackers to gain administrative privileges.

EPMM versions 12.10.0.0, 12.9.0.2, and 12.8.0.4 were released on Tuesday to resolve CVE-2026-18851, another high-severity authentication bypass. Unlike the Sentry bug, this one requires authentication for successful exploitation.

Ivanti says it is not aware of any of these vulnerabilities being exploited in the wild. No other Ivanti products are affected, the company notes.

Also on Tuesday, Citrix announced fixes for two medium-severity flaws in its Workspace app for Windows: an out-of-bounds read that requires local access, and an out-of-bounds write that requires physical access to an affected system.

Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Related: N-able Patches Critical Zero-Day in N-central

Related: 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/ivanti-patches-critical-flaws-across-enterprise-security-products/