Posting Date: 2026/09/17

【Vulnerability Alert】Ivanti Neurons for ITSM Contains 8 High-Risk Security Vulnerabilities

  • Subject:【Vulnerability Alert】Ivanti Neurons for ITSM Contains 8 High-Risk Security Vulnerabilities


  • Description:
    • Forwarded from TWCERT/CC Security Advisory TWCERTCC-200-202609-00000010
    • ITSM is a reliable and powerful IT service management solution under the Ivanti brand, helping organizations improve service efficiency and ensure IT operational compliance and security. Ivanti recently issued a major security advisory for Ivanti Neurons for ITSM, disclosing 8 high-risk security vulnerabilities in the product.
    • CVE-2026-12744 (CVSS: 9.8) is a deserialization of untrusted data vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.
    • CVE-2026-12745 (CVSS: 9.8) is a deserialization of untrusted data vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.
    • CVE-2026-12651 (CVSS: 8.8) is a deserialization of untrusted data vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
    • CVE-2026-12650 (CVSS: 9.9) is a deserialization of untrusted data vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
    • CVE-2026-12648 (CVSS: 8.8) is a deserialization of untrusted data vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
    • CVE-2026-12645 (CVSS: 9.9) is a missing authorization vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
    • CVE-2026-12646 (CVSS: 9.9) is a missing authorization vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
    • CVE-2026-12647 (CVSS: 9.9) is a missing authorization vulnerability, allowing authenticated remote attackers to execute arbitrary code on the server.
  • Affected Platforms:
    • Ivanti Neurons for ITSM (Cloud / SaaS) version 2026.2
    • Ivanti Neurons for ITSM On-Prem versions 2025.2, 2025.3, 2025.4, 2026.1
  • Recommended Actions:
    • Please update to the following versions:
    • Ivanti Neurons for ITSM (Cloud / SaaS) mo2026.2 and later
    • Ivanti Neurons for ITSM On-Prem 2025.2 Sept 2026 Security Patch
    • Ivanti Neurons for ITSM On-Prem 2025.3 Sept 2026 Security Patch
    • Ivanti Neurons for ITSM On-Prem 2025.4 Sept 2026 Security Patch
    • Ivanti Neurons for ITSM On-Prem 2026.1 Sept 2026 Security Patch
    • Ivanti Neurons for ITSM On-Prem 2026.2 and later
  • References:

Computer and Communication Center
Network System Division