Your ITSM console should not accept stranger serialization. Ivanti’s September batch includes two unauthenticated remote code execution bugs in Neurons for ITSM — and on-prem operators still need to land the fix.
What happened
On September 8–9, 2026, Ivanti disclosed a cluster of critical and high bugs across Neurons for ITSM, Sentry, and EPMM. Inside Neurons for ITSM, six issues rate critical; the two that matter most for internet-facing risk are CVE-2026-12744 and CVE-2026-12745 — deserialization of untrusted data (CWE-502) that a remote attacker can hit without authentication, scoring CVSS 9.8.
Ivanti also fixed related missing-authorization and authenticated deserialization issues (including CVE-2026-12647 / 12645 / 12646 / 12650 at 9.9). Cloud/SaaS tenants were patched by Ivanti earlier; on-premises customers must apply the September 2026 security updates for trains 2025.2 through 2026.1, or move to 2026.2 (fixes included; rollout window around September 21).
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Ivanti states it has no evidence of in-the-wild exploitation as of the advisory — treat that as a head start, not a hall pass.
Why it matters
ITSM platforms hold tickets, attachments, credentials, discovery data, and often privileged connectors into AD, email, and endpoints. Unauth RCE on that brain is a one-request path from “self-service portal on the internet” to “operator on your helpdesk stack.” Even when exploitation is not yet observed, CVSS 9.8 unauth deserialization historically does not stay quiet once PoCs circulate.
What to do first
- Confirm whether you run on-prem Neurons for ITSM. SaaS: verify Ivanti’s cloud fix landed. On-prem: apply September 2026 security updates for 2025.2 / 2025.3 / 2025.4 / 2026.1, or upgrade to 2026.2+.
- Pull any self-service / customer portal URLs off the public internet until patched — or put them behind SSO + IP allowlists.
- Review admin creation, plugin/extension installs, and unexpected process trees on the ITSM hosts since early September.
- While you are in the Ivanti batch: patch Sentry (CVE-2026-83527 unauth auth-bypass to admin) and EPMM (CVE-2026-18851) on the same change window if those products are in scope.
Details
- CVEs (unauth RCE): CVE-2026-12744, CVE-2026-12745 (CVSS 9.8, CWE-502)
- Related critical (authz / deser): CVE-2026-12647, CVE-2026-12645, CVE-2026-12646, CVE-2026-12650 (CVSS 9.9)
- Product: Ivanti Neurons for ITSM (on-prem before 2026.2; cloud patched by vendor)
- Fixed: September 2026 security updates for 2025.2–2026.1; included in 2026.2
- Exploitation (vendor): None known at disclosure
- KEV: Not listed as of brief build
Hunt / verify
- Confirm build/version string shows a September-patched train or 2026.2+.
- Inventory internet-exposed ITSM and self-service URLs; compare to CMDB.
- Hunt web logs for anomalous POSTs with serialization payloads to ITSM endpoints pre-patch.
- Spot-check service accounts the ITSM host can reach (AD, SMTP, RMM, cloud APIs).
Sources
- https://www.ivanti.com/en-gb/blog/september-2026-security-update
- https://www.securityweek.com/ivanti-patches-critical-flaws-across-enterprise-security-products/
- https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US
- https://nvd.nist.gov/vuln/detail/CVE-2026-12745
- https://nvd.nist.gov/vuln/detail/CVE-2026-12744
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.