Posting Date: 2026/09/17
【Vulnerability Alert】Ivanti Neurons for ITSM Contains 8 High-Risk Security Vulnerabilities
- Subject:【Vulnerability Alert】Ivanti Neurons for ITSM Contains 8 High-Risk Security Vulnerabilities
- Description:
- Forwarded from TWCERT/CC Security Advisory TWCERTCC-200-202609-00000010
- ITSM is a reliable and powerful IT service management solution under the Ivanti brand, helping organizations improve service efficiency and ensure IT operational compliance and security. Ivanti recently issued a major security advisory for Ivanti Neurons for ITSM, disclosing 8 high-risk security vulnerabilities in the product.
- CVE-2026-12744 (CVSS: 9.8) is a deserialization of untrusted data vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.
- CVE-2026-12745 (CVSS: 9.8) is a deserialization of untrusted data vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.
- CVE-2026-12651 (CVSS: 8.8) is a deserialization of untrusted data vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
- CVE-2026-12650 (CVSS: 9.9) is a deserialization of untrusted data vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
- CVE-2026-12648 (CVSS: 8.8) is a deserialization of untrusted data vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
- CVE-2026-12645 (CVSS: 9.9) is a missing authorization vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
- CVE-2026-12646 (CVSS: 9.9) is a missing authorization vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
- CVE-2026-12647 (CVSS: 9.9) is a missing authorization vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
- Affected Platforms:
- Ivanti Neurons for ITSM (Cloud / SaaS) version 2026.2
- Ivanti Neurons for ITSM On-Prem versions 2025.2, 2025.3, 2025.4, 2026.1
- Recommended Actions:
- Please update to the following versions:
- Ivanti Neurons for ITSM (Cloud / SaaS) mo2026.2 and later
- Ivanti Neurons for ITSM On-Prem 2025.2 Sept 2026 Security Patch
- Ivanti Neurons for ITSM On-Prem 2025.3 Sept 2026 Security Patch
- Ivanti Neurons for ITSM On-Prem 2025.4 Sept 2026 Security Patch
- Ivanti Neurons for ITSM On-Prem 2026.1 Sept 2026 Security Patch
- Ivanti Neurons for ITSM On-Prem 2026.2 and later
- References:
Computer and Communication Center
Network System Division