Ivanti Patches Critical Flaws Across Enterprise Security Products
Ivanti released security patches for critical and high-severity vulnerabilities across Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) Neurons for ITSM received the most fixes: eight bugs total, six rated critical, including missing authorization flaws (CVSS 9.9) and unsafe deserialization issues leading to remote code execution Two vulnerabilities (CVE-2026-12744 and CVE-2026-12745) can be exploited without authentication, making them particularly dangerous Sentry and EPMM each rec
Analysis
TL;DR
- Ivanti released security patches for critical and high-severity vulnerabilities across Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM)
- Neurons for ITSM received the most fixes: eight bugs total, six rated critical, including missing authorization flaws (CVSS 9.9) and unsafe deserialization issues leading to remote code execution
- Two vulnerabilities (CVE-2026-12744 and CVE-2026-12745) can be exploited without authentication, making them particularly dangerous
- Sentry and EPMM each received patches for high-severity authentication bypass vulnerabilities (CVE-2026-83527 and CVE-2026-18851 respectively)
- Ivanti reports no known active exploitation in the wild; updates are available for multiple product versions
Why It Matters
This is a significant security event for organizations relying on Ivanti's IT service management and endpoint management platforms, as multiple critical vulnerabilities could allow unauthenticated remote code execution. The fact that some flaws require no authentication makes immediate patching essential for on-premises deployments. IT security teams should treat this as a priority update cycle to prevent potential compromise of enterprise IT infrastructure.
Technical Details
- Neurons for ITSM: Eight vulnerabilities patched across versions 2025.2, 2025.3, 2025.4, and 2026.1 (with 2026.2 scheduled for September 21). Six critical flaws include CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646 (missing authorization, CVSS 9.9) and CVE-2026-12650, CVE-2026-12744, CVE-2026-12745 (deserialization of untrusted data, CVSS 9.8-9.9). Two high-severity deserialization bugs (CVE-2026-12651, CVE-2026-12648) also enable remote code execution.
- Sentry: Versions R10.8.2, R10.7.3, and R10.6.4 patch CVE-2026-83527, a high-severity authentication bypass allowing unauthenticated attackers to gain administrative privileges.
- EPMM: Versions 12.10.0.0, 12.9.0.2, and 12.8.0.4 address CVE-2026-18851, a high-severity authentication bypass that requires prior authentication for exploitation.
- All vulnerabilities were disclosed through Ivanti's advisory with no evidence of active exploitation at time of release.
Industry Insight
- Organizations running Ivanti Neurons for ITSM on-premises should prioritize immediate patching, especially given the unauthenticated exploitability of two critical CVEs—delay increases exposure to remote code execution attacks.
- The concentration of deserialization and authorization flaws in enterprise ITSM platforms highlights the ongoing risk in legacy software supply chains; vendors and customers should adopt continuous vulnerability monitoring and automated patch management.
- With no known active exploitation reported, this represents a proactive security update window—teams should verify patch deployment across all supported versions before threat actors potentially weaponize the disclosed flaws.
Disclaimer: The above content is generated by AI and is for reference only.