Ivanti Neurons for ITSM Multiple Critical Vulnerabilities
Release Date: 15th September 2026 (Added 16 September 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that operate Ivanti Neurons for ITSM for IT service management and help desk operations. This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-12645, CVE-2026-12646, CVE-2026-12647, CVE-2026-12650, CVE-2026-12744, and CVE-2026-12745 are six critical vulnerabilities in Ivanti Neurons for ITSM, a widely-deployed enterprise IT service management (ITSM) and help desk platform used by government agencies and large organizations globally. Ivanti products have a well-documented history of being targeted by attackers, including prior nation-state exploitation of other Ivanti solutions. CVE-2026-12645, CVE-2026-12646, and CVE-2026-12647 are missing-authorization flaws, and CVE-2026-12650 is a deserialization-of-untrusted-data flaw with a scope change into components beyond the vulnerable module.
All four require an attacker to already hold authenticated access, but can then be used to achieve arbitrary code execution. CVE-2026-12744 and CVE-2026-12745 are deserialization-of-untrusted-data flaws that require no authentication at all, and are the most severe of the six. All six affect Ivanti Neurons for ITSM versions 2025.2 through 2026.1 and are resolved by the same upgrade, so they are combined into this single advisory.
What are the systems affected?
Affected systems are any Ivanti Neurons for ITSM instance running a pre-patch version.
Ivanti Neurons for ITSM, versions 2025.2 through 2026.1 - (Affected)
Ivanti Neurons for ITSM, version 2026.2 and later - (Not affected, patched)
Any instance reachable from an untrusted network faces critical risk: two of the six flaws require no authentication at all.
What does this mean?
No user interaction is required for any of the six flaws. Ivanti reports no evidence of active exploitation at the time of disclosure, but the two fully unauthenticated deserialization flaws make this a high-priority patching target for any organization operating Neurons for ITSM.
Step 1 - Reach the ITSM Platform and Exploit Deserialization or Authorization Flaws
An unauthenticated remote attacker sends specially crafted serialized data to a reachable Ivanti Neurons for ITSM instance to exploit CVE-2026-12744 or CVE-2026-12745, achieving remote code execution with no credentials. Separately, an attacker who already holds authenticated access can exploit the missing-authorization flaws (CVE-2026-12645, CVE-2026-12646, CVE-2026-12647) or the authenticated deserialization flaw (CVE-2026-12650) to achieve arbitrary code execution or impact components beyond the vulnerable module.
Step 2 - Achieve Code Execution and Pivot Within the ITSM Environment
Once exploited, any of the six flaws can result in arbitrary code execution on the ITSM server, which holds sensitive service-desk data, credentials, and integrations that could be leveraged to move further into the organization's environment.
Successful exploitation may allow an attacker to execute arbitrary code on an Ivanti Neurons for ITSM server, in some cases without any authentication at all, and to access or manipulate sensitive service-desk records, credentials, and integrations managed through the platform.
Mitigation process?
CERTVU recommends the following:
-
Apply the Vendor Patch Without Delay
Upgrade Ivanti Neurons for ITSM to version 2026.2 or later as a priority change, given the presence of two unauthenticated, network-exploitable critical deserialization flaws. -
Restrict Network Exposure of the ITSM Platform
Limit access to the Ivanti Neurons for ITSM platform to trusted internal networks or a VPN, and avoid exposing it directly to the internet, particularly while patching is pending. -
Review Authenticated Accounts and Access Levels
Review existing ITSM accounts and their access levels, disable unused or unnecessary accounts, and ensure credentials have not been reused or compromised elsewhere. -
Review ITSM Server and Application Logs for Unusual Activity
Check ITSM server and application logs for unexpected deserialization errors, unusual requests, or signs of unauthorized privilege use.
Report any suspected compromise involving an Ivanti Neurons for ITSM instance to CERTVU at
Reference
- https://www.cve.org/CVERecord?id=CVE-2026-12744
- https://www.cve.org/CVERecord?id=CVE-2026-12650
- https://www.ivanti.com/blog/september-2026-security-update
- Download advisory (English): Ivanti Neurons for ITSM Multiple Critical Vulnerabilities