TL;DR
Ivanti patched eight vulnerabilities in its Neurons for ITSM platform, including five rated Critical with CVSS scores up to 9.9. Three of the flaws allow unauthenticated remote code execution. Ivanti has confirmed no customers were exploited at the time of disclosure.
- Total: 8 CVEs
- Severity: 6 Critical · 2 High
- Actively exploited: None confirmed
- Highest severity: 9.9 (Critical · CVSSv3) — CVE-2026-12650
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-12650 | 9.9 | CWE-502 | 2026.2 | Not exploited |
| CVE-2026-12645 | 9.9 | CWE-862 | 2026.2 | Not exploited |
| CVE-2026-12646 | 9.9 | CWE-862 | 2026.2 | Not exploited |
| CVE-2026-12647 | 9.9 | CWE-862 | 2026.2 | Not exploited |
| CVE-2026-12744 | 9.8 | CWE-502 | 2026.2 | Not exploited |
| CVE-2026-12745 | 9.8 | CWE-502 | 2026.2 | Not exploited |
| CVE-2026-12651 | 8.8 | CWE-502 | 2026.2 | Not exploited |
| CVE-2026-12648 | 8.8 | CWE-502 | 2026.2 | Not exploited |
Why This Matters
Ivanti Neurons for ITSM is an enterprise IT service management platform used by organizations worldwide. Attackers who exploit these flaws could run arbitrary commands directly on the server. That gives them control over internal ticketing, asset data, and potentially wider network access.
The discovery method adds further urgency. Ivanti found these vulnerabilities using advanced large language models – AI tooling that can surface bugs traditional scanners miss. That same technique is available to attackers, narrowing the detection window for defenders.
How the Attacks Work
Unauthenticated Deserialization (CVE-2026-12744, CVE-2026-12745)
Two critical flaws – both CWE-502 Deserialization of Untrusted Data, CVSS 9.8 – let a remote attacker with no credentials at all execute arbitrary code on the server. The attacker simply sends a malicious serialized payload over the network. No login, no privileges, and no user interaction are required.
Authenticated RCE Flaws (CVE-2026-12650, CVE-2026-12648, CVE-2026-12651)
Three additional deserialization bugs affect authenticated attackers. CVE-2026-12650 scores 9.9 (Critical) because its scope is changed – a compromise can spill beyond the vulnerable component. CVE-2026-12648 and CVE-2026-12651 both score 8.8 (High). All three require only low-level privileges.
Missing Authorization Flaws (CVE-2026-12645, CVE-2026-12646, CVE-2026-12647)
Three CWE-862 Missing Authorization vulnerabilities each score 9.9 (Critical). A low-privileged authenticated user can trigger protected server-side functionality without proper checks. This again results in arbitrary code execution on the server.
Affected Versions
All eight CVEs affect Ivanti Neurons for ITSM versions before 2026.2. On-premises deployments running 2025.2, 2025.3, 2025.4, and 2026.1 are all in scope. Cloud and SaaS customers were already protected – Ivanti applied the fix to all cloud landscapes on August 9, 2026.
Patch and Mitigation Steps
On-premises administrators should apply one of the September 2026 Security Patches for their respective version – 2025.2, 2025.3, 2025.4, or 2026.1 – available now in the Ivanti License Server (ILS). Version 2026.2 for on-premises will also include the fixes when it releases on September 21, 2026.
Ivanti notes that risk is significantly lower for on-premises deployments that are not exposed to the internet. Isolating the ITSM instance behind a firewall or VPN is a practical interim step if immediate patching is not possible. No action is needed for cloud customers.
Ivanti has confirmed no exploitation in the wild at the time of disclosure. No public proof-of-concept has been reported. Even so, the unauthenticated attack surface and high CVSS scores make rapid patching a priority.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!