Ivanti Neurons for ITSM Multiple Critical Vulnerabilities

Release Date: 15th September 2026 (Added 16 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate Ivanti Neurons for ITSM for IT service management and help desk operations. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-12645, CVE-2026-12646, CVE-2026-12647, CVE-2026-12650, CVE-2026-12744, and CVE-2026-12745 are six critical vulnerabilities in Ivanti Neurons for ITSM, a widely-deployed enterprise IT service management (ITSM) and help desk platform used by government agencies and large organizations globally. Ivanti products have a well-documented history of being targeted by attackers, including prior nation-state exploitation of other Ivanti solutions. CVE-2026-12645, CVE-2026-12646, and CVE-2026-12647 are missing-authorization flaws, and CVE-2026-12650 is a deserialization-of-untrusted-data flaw with a scope change into components beyond the vulnerable module.

All four require an attacker to already hold authenticated access, but can then be used to achieve arbitrary code execution. CVE-2026-12744 and CVE-2026-12745 are deserialization-of-untrusted-data flaws that require no authentication at all, and are the most severe of the six. All six affect Ivanti Neurons for ITSM versions 2025.2 through 2026.1 and are resolved by the same upgrade, so they are combined into this single advisory.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-12744
  2. https://www.cve.org/CVERecord?id=CVE-2026-12650
  3. https://www.ivanti.com/blog/september-2026-security-update