Forwarded from TWCERT/CC Security Advisory TWCERTCC-200-202609-00000010
ITSM is a reliable and powerful IT service management solution under the Ivanti brand, helping organizations improve service efficiency and ensure IT operational compliance and security. Ivanti recently issued a major security advisory for Ivanti Neurons for ITSM, disclosing 8 high-risk security vulnerabilities in the product.
CVE-2026-12744 (CVSS: 9.8) is a deserialization of untrusted data vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.
CVE-2026-12745 (CVSS: 9.8) is a deserialization of untrusted data vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.
CVE-2026-12651 (CVSS: 8.8) is a deserialization of untrusted data vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
CVE-2026-12650 (CVSS: 9.9) is a deserialization of untrusted data vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
CVE-2026-12648 (CVSS: 8.8) is a deserialization of untrusted data vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
CVE-2026-12645 (CVSS: 9.9) is a missing authorization vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
CVE-2026-12646 (CVSS: 9.9) is a missing authorization vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
CVE-2026-12647 (CVSS: 9.9) is a missing authorization vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.