Ivanti has released September 2026 security updates addressing 10 vulnerabilities across Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM). The most serious issues affect Neurons for ITSM, where six critical vulnerabilities can lead to remote code execution. Two of these can be exploited without authentication. Ivanti stated that it is not aware of exploitation in the wild.
CVE-2026-12647 (CVSS 9.9 – Critical): A missing authorization vulnerability in Ivanti Neurons for ITSM that can allow a remote authenticated attacker to execute arbitrary code on the server.
CVE-2026-12645 (CVSS 9.9 – Critical): A missing authorization vulnerability in Neurons for ITSM that can lead to remote code execution by an authenticated attacker.
CVE-2026-12646 (CVSS 9.9 – Critical): A missing authorization vulnerability that can be exploited by a remote authenticated attacker to execute arbitrary code on the affected Neurons for ITSM server.
CVE-2026-12650 (CVSS 9.9 – Critical): A deserialization of untrusted data vulnerability in Neurons for ITSM that can enable remote authenticated attackers to execute arbitrary code.
CVE-2026-12744 (CVSS 9.8 – Critical): A deserialization of untrusted data vulnerability that allows a remote unauthenticated attacker to execute arbitrary code on the Neurons for ITSM server.
CVE-2026-12745 (CVSS 9.8 – Critical): Another critical deserialization vulnerability that can be exploited remotely without authentication to achieve arbitrary code execution.
CVE-2026-12651 (CVSS 8.8 – High): A deserialization of untrusted data vulnerability in Neurons for ITSM that can lead to remote code execution by an authenticated attacker.
CVE-2026-12648 (CVSS 8.8 – High): A deserialization of untrusted data vulnerability allowing a remote authenticated attacker to execute arbitrary code.
CVE-2026-83527 (CVSS 8.1 – High): An authentication bypass vulnerability in Ivanti Sentry that allows a remote unauthenticated attacker to obtain administrative-level access.
CVE-2026-18851 (CVSS 8.8 – High): A missing authorization vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that requires authentication and can allow a remote attacker to escalate privileges to administrator.[/subscribe_to_unlock_form]
Ivanti has released September 2026 security updates addressing 10 vulnerabilities across Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM). The most serious issues affect Neurons for ITSM, where six critical vulnerabilities can lead to remote code execution. Two of these can be exploited without authentication. Ivanti stated that it is not aware of exploitation in the wild.
CVE-2026-12647 (CVSS 9.9 – Critical): A missing authorization vulnerability in Ivanti Neurons for ITSM that can allow a remote authenticated attacker to execute arbitrary code on the server.
CVE-2026-12645 (CVSS 9.9 – Critical): A missing authorization vulnerability in Neurons for ITSM that can lead to remote code execution by an authenticated attacker.
CVE-2026-12646 (CVSS 9.9 – Critical): A missing authorization vulnerability that can be exploited by a remote authenticated attacker to execute arbitrary code on the affected Neurons for ITSM server.
CVE-2026-12650 (CVSS 9.9 – Critical): A deserialization of untrusted data vulnerability in Neurons for ITSM that can enable remote authenticated attackers to execute arbitrary code.
CVE-2026-12744 (CVSS 9.8 – Critical): A deserialization of untrusted data vulnerability that allows a remote unauthenticated attacker to execute arbitrary code on the Neurons for ITSM server.
CVE-2026-12745 (CVSS 9.8 – Critical): Another critical deserialization vulnerability that can be exploited remotely without authentication to achieve arbitrary code execution.
CVE-2026-12651 (CVSS 8.8 – High): A deserialization of untrusted data vulnerability in Neurons for ITSM that can lead to remote code execution by an authenticated attacker.
CVE-2026-12648 (CVSS 8.8 – High): A deserialization of untrusted data vulnerability allowing a remote authenticated attacker to execute arbitrary code.
CVE-2026-83527 (CVSS 8.1 – High): An authentication bypass vulnerability in Ivanti Sentry that allows a remote unauthenticated attacker to obtain administrative-level access.
CVE-2026-18851 (CVSS 8.8 – High): A missing authorization vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that requires authentication and can allow a remote attacker to escalate privileges to administrator.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]