ZeroHour
GBHackerspublished ()ingested Divya

Ivanti Patches 10 EPMM, Neurons for ITSM and Sentry Flaws Enabling RCE and Admin Access

AI summary · glm-5.3-flash

Ivanti patches 10 flaws in EPMM, Neurons for ITSM, and Sentry, including two 9.8-rated unauthenticated RCEs in ITSM.

Ivanti released fixes for 10 vulnerabilities across Endpoint Manager Mobile, Neurons for ITSM, and Sentry, and said it was not aware of active exploitation at disclosure. The most severe are CVE-2026-12744 and CVE-2026-12745, unauthenticated deserialization RCEs rated 9.8 in Neurons for ITSM, alongside authenticated deserialization and missing-authorization RCEs rated up to 9.9. CVE-2026-18851 is an 8.8-rated EPMM privilege escalation to administrator, and CVE-2026-83527 is an 8.1-rated unauthenticated authentication bypass in Sentry granting administrative access. Ivanti said the ITSM weaknesses were found using large language models; Cloud/SaaS fixes shipped August 9, 2026, and on-premises patches are available from September 2026.

  • Two unauthenticated 9.8 deserialization RCEs (CVE-2026-12744, CVE-2026-12745) affect Neurons for ITSM
  • Missing-authorization flaws rated 9.9 allow authenticated attackers arbitrary code execution
  • CVE-2026-18851 (8.8) lets authenticated EPMM users escalate to administrator
  • CVE-2026-83527 (8.1) bypasses Sentry authentication for administrative access
  • ITSM weaknesses found using LLMs; on-premises patch available September 2026

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-12645
+2 in the same advisory: …12646 …12647
Missing Authorization Flaw Enables Authenticated RCE in Ivanti Neurons for ITSM

CVE-2026-12645 is a critical Missing Authorization flaw (CWE-862) in Ivanti Neurons for ITSM, Ivanti's IT service management platform, where functionality on the server can be reached without the required authorization checks. A remote attacker who already holds valid low-privileged credentials can trigger the flaw with crafted requests to the affected component, and because the check is absent they can execute arbitrary code on the server. The CVSS scope-changed metric (S:C) indicates that successful exploitation may impact resources beyond the vulnerable component, with high impact to confidentiality, integrity, and availability. Organizations running Ivanti Neurons for ITSM in versions before 2026.2 are affected; the fix shipped as part of a batch of 10 patches across Ivanti's EPMM, Neurons for ITSM, and Sentry products. No exploitation in the wild, public proof-of-concept, or KEV listing is known, and EPSS currently estimates about a 1.2% probability of exploitation in the next 30 days.

Do: Upgrade Ivanti Neurons for ITSM to version 2026.2 or later per Ivanti's advisory. Until patched, restrict which accounts can reach the platform, watch for anomalous authenticated activity and unexpected server-side code execution, and check Ivanti's advisory for any interim mitigation or workaround guidance. Because exploitation requires valid credentials, also review accounts with low-privileged access to the ITSM instance for signs of compromise.

9.91%
  • Ivanti Neurons for ITSM all versions before 2026.2
largeroughly 1,000-10,000 enterprise deployments/tenants, with aggregate internal users plausibly in the hundreds of thousands (exact counts not publicly published)
CVE-2026-12650
+2 in the same advisory: …12648 …12651
Authenticated Deserialization RCE in Ivanti Neurons for ITSM

Ivanti Neurons for ITSM versions before 2026.2 contain a deserialization of untrusted data flaw (CWE-502) that allows remote code execution. A remote attacker who already holds valid (low-privilege) credentials sends crafted serialized data to the server, triggering the flaw; the CVSS scope-changed rating (9.9) indicates successful exploitation affects resources beyond the vulnerable component, effectively compromising the underlying server. An attacker gains arbitrary code execution on the ITSM server, with high impact on confidentiality, integrity, and availability. Any organization running an affected version of Ivanti Neurons for ITSM is exposed, though the authentication requirement means instances that are internet-facing or that expose accounts to partners/customers carry the highest risk. As of the data available, there is no evidence of in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA KEV; EPSS estimates roughly a 1.5% chance of exploitation within 30 days (72nd percentile).

Do: Upgrade Ivanti Neurons for ITSM to version 2026.2 or later, and apply Ivanti's current patch bundle covering the related EPMM, Neurons, and Sentry flaws. Until patched, review whether the ITSM instance is internet-exposed, audit and restrict which accounts can reach it (disable stale or partner-facing credentials), and monitor Ivanti advisories for news of active exploitation since exploitation requires valid authentication.

9.9
group max
1%
  • Ivanti Neurons for ITSM all versions before 2026.2
moderateon the order of thousands of deployments (one server or cloud tenant per customer); no public install counts
CVE-2026-12744
+1 in the same advisory: …12745
Unauthenticated Deserialization RCE in Ivanti Neurons for ITSM

CVE-2026-12744 is a deserialization of untrusted data flaw (CWE-502) in Ivanti Neurons for ITSM that allows a remote, unauthenticated attacker to execute arbitrary code on the server. It is triggered by sending crafted serialized input to the network-exposed ITSM service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms the attack requires no privileges, no user interaction, and low complexity. Successful exploitation yields full server compromise, with high impact to confidentiality, integrity, and availability. All organizations running Ivanti Neurons for ITSM on any release before 2026.2 are affected, with internet-exposed or broadly reachable deployments at greatest risk. There is no known public proof-of-concept, the flaw is not yet in CISA's KEV, and EPSS estimates a 2.2% probability of exploitation within 30 days, but the patch shipped as part of a recent batch of Ivanti fixes, so defenders should treat it as a priority despite the absence of confirmed exploitation.

Do: Upgrade Ivanti Neurons for ITSM to version 2026.2 or later. Until patched, restrict network access to the ITSM server to trusted ranges (e.g., internal-only firewall rules or VPN), since unauthenticated attackers on any reachable network path can attempt exploitation. Because this fix was released alongside a batch of Ivanti patches covering EPMM, Neurons, and Sentry, review and apply the full advisory set rather than this CVE alone.

9.82%
  • Ivanti Neurons for ITSM all versions before 2026.2
moderate~1,000-10,000 server instances/tenants (exact install base unknown)
CVE-2026-18851
Missing Authorization in Ivanti Endpoint Manager Mobile Allows Admin Privilege Escalation

CVE-2026-18851 is a missing-authorization flaw (CWE-862) in Ivanti Endpoint Manager Mobile (EPMM) in which certain functionality fails to verify that an authenticated user is authorized to perform administrative actions. A remote attacker who already holds a valid low-privilege session can send crafted requests over the network, with no user interaction required, and escalate to administrator. From an admin position, the attacker gains full control of the mobile device management console, including access to managed-device data and the ability to alter or push configurations to enrolled devices. Organizations running EPMM versions before 12.10.0.0, 12.9.0.2, or 12.8.0.4 are affected. As of the advisory there is no known in-the-wild exploitation and no public proof-of-concept, it is not in CISA KEV (EPSS ~1.0%), and it was patched as part of a larger Ivanti batch covering EPMM, Neurons for ITSM and Sentry flaws enabling RCE and admin access.

Do: Upgrade EPMM to 12.10.0.0, 12.9.0.2, or 12.8.0.4 depending on the release branch in use, per Ivanti's advisory. Until patched, restrict EPMM console/API interfaces to trusted networks and review logs for authenticated users performing unexpected administrative actions. Because this fix ships in the same batch as other EPMM, Neurons for ITSM and Sentry patches, apply the full set of vendor updates rather than only this CVE.

8.81%
  • Ivanti Endpoint Manager Mobile (EPMM) All versions before 12.10.0.0, 12.9.0.2, and 12.8.0.4 (each supported release branch); fixed in 12.10.0.0, 12.9.0.2, and 12.8.0.4
massplausibly >1,000,000 managed devices/users across tens of thousands of enterprise and government deployments
CVE-2026-83527
Authentication Bypass in Ivanti Sentry Grants Remote Admin Access

CVE-2026-83527 is an authentication bypass (CWE-288) in Ivanti Sentry that allows a remote, unauthenticated attacker to gain administrative-level access to the appliance. It is triggered over the network with no prior privileges or user interaction, though the high-attack-complexity (AC:H) CVSS rating indicates exploitation depends on specific conditions rather than a trivially reliable path. A successful attacker obtains admin-level control of Sentry, the gateway component many organizations deploy alongside Ivanti EPMM/MobileIron for mobile device management, potentially exposing or disrupting device-management functions. Any organization running Ivanti Sentry on builds earlier than the fixed releases R10.8.2, R10.7.3, or R10.6.4 (depending on release line) is affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS assigns a 1.5% probability of exploitation within 30 days, so active exploitation is not currently confirmed.

Do: Upgrade Ivanti Sentry to R10.8.2 (or R10.7.3 / R10.6.4 for the corresponding release line) as addressed in Ivanti's advisory AV26-897. Until patched, minimize Sentry's internet exposure to required management/enrollment traffic and review appliance logs for unexpected administrator logins. Ivanti EPMM and Neurons for ITSM administrators should also review the same advisory, which covers additional flaws in those products.

8.11%
  • Ivanti Sentry All builds before R10.8.2, before R10.7.3, and before R10.6.4 (fixed in R10.8.2, R10.7.3, and R10.6.4, per release line)
nichelikely low-thousands of deployments, with only a few hundred internet-exposed instances in past public scans
Full article453 words · extracted from gbhackers.com · click to collapse

Ivanti has released security updates addressing 10 vulnerabilities in Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry.

The vulnerabilities include several critical remote code execution (RCE) issues in Neurons for ITSM, an authentication bypass in Sentry that could grant administrative access, and a privilege escalation flaw in EPMM.

Ivanti Patches 10 EPMM Flaws

The company said it was not aware of any active exploitation of these vulnerabilities at the time of disclosure. However, organizations using exposed on-premises ITSM infrastructure, mobile device management deployments, or Sentry gateways should prioritize patching, as some of these issues could lead to complete system compromise.

The most severe vulnerabilities affect Ivanti Neurons for ITSM before version 2026.2. CVE-2026-12744 and CVE-2026-12745 are unauthenticated deserialization vulnerabilities, both rated 9.8 out of 10, which allow remote attackers to execute arbitrary code on the server.

These vulnerabilities are categorized as CWE-502, relating to the deserialization of untrusted data, a weakness often leading to complete server compromise when attacker-controlled serialized objects are processed unsafely.

Ivanti has also addressed three additional authenticated deserialization flaws: CVE-2026-12651 and CVE-2026-12648, both rated 8.8, and CVE-2026-12650, rated 9.9.

Although these require valid low-privileged credentials, the 9.9-rated issue has a changed scope, meaning that a compromise could impact components beyond the vulnerable security authority.

Additionally, three missing authorization issues, CVE-2026-12645, CVE-2026-12646, and CVE-2026-12647, each rated 9.9, allow a remote authenticated attacker to execute arbitrary code.

Ivanti noted that the vulnerabilities in Neurons for ITSM were discovered using advanced large language models to identify weaknesses that conventional security tools had overlooked.

Ivanti released fixes for Cloud/SaaS deployments on August 9, 2026. On-premises customers using versions 2025.2 through 2026.1 should apply the relevant security patch from September 2026 or upgrade to version 2026.2.

Separately, CVE-2026-18851 affects Ivanti Endpoint Manager Mobile. This missing authorization flaw, rated 8.8, enables a remote authenticated attacker to escalate privileges to an administrator level. It impacts EPMM versions 12.9.0.1 and earlier, as well as 12.8.0.3 and earlier. This issue has been resolved in versions 12.10.0.0, 12.9.0.2, and 12.8.0.4.

The final issue, CVE-2026-83527, is an authentication bypass in Ivanti Sentry. Rated 8.1, this flaw lets a remote, unauthenticated attacker gain administrative access to vulnerable Sentry instances managed by EPMM or Ivanti Neurons for MDM. Sentry versions R10.8.2, R10.7.3, and R10.6.4 include a fix.

Administrators should inventory their internet-facing Ivanti systems, apply available updates, review privileged accounts and administrative actions, and investigate any unusual activity on Sentry or ITSM servers.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/ivanti-patches-10-epmm-neurons-for-itsm-and-sentry-flaws/