Ivanti Neurons for ITSM: Unauth Deserialization RCE Pair (CVE-2026-12744 / 12745)

By George Bailey   Published: 09/21/26   Updated: 09/21/26   3 min read

Your ITSM console should not accept stranger serialization. Ivanti’s September batch includes two unauthenticated remote code execution bugs in Neurons for ITSM — and on-prem operators still need to land the fix.

What happened

On September 8–9, 2026, Ivanti disclosed a cluster of critical and high bugs across Neurons for ITSM, Sentry, and EPMM. Inside Neurons for ITSM, six issues rate critical; the two that matter most for internet-facing risk are CVE-2026-12744 and CVE-2026-12745 — deserialization of untrusted data (CWE-502) that a remote attacker can hit without authentication, scoring CVSS 9.8.

Ivanti also fixed related missing-authorization and authenticated deserialization issues (including CVE-2026-12647 / 12645 / 12646 / 12650 at 9.9). Cloud/SaaS tenants were patched by Ivanti earlier; on-premises customers must apply the September 2026 security updates for trains 2025.2 through 2026.1, or move to 2026.2 (fixes included; rollout window around September 21).

Ivanti states it has no evidence of in-the-wild exploitation as of the advisory — treat that as a head start, not a hall pass.

Why it matters

ITSM platforms hold tickets, attachments, credentials, discovery data, and often privileged connectors into AD, email, and endpoints. Unauth RCE on that brain is a one-request path from “self-service portal on the internet” to “operator on your helpdesk stack.” Even when exploitation is not yet observed, CVSS 9.8 unauth deserialization historically does not stay quiet once PoCs circulate.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.