IVANTI Neurons for ITSM owners face eight reported vulnerabilities, including five rated critical with CVSS scores up to 9.9. Three of the flaws allow unauthenticated remote code execution, while three are authenticated deserialisation issues and three more are missing-authorization flaws. Ivanti states that no customers were exploited at disclosure time. The most severe entry is CVE-2026-12650, scored 9.9, with a broader impact due to its scope.
Other high-severity entries include CVE-2026-12744 and CVE-2026-12745 (both 9.8) for unauthenticated deserialisation, and CVE-12648, CVE-12651 (both 8.8) tied to authenticated deserialisation or missing authorisation, respectively. A further trio—CVE-12645, CVE-12646 and CVE-12647—are all missing-authorization vulnerabilities, each scoring 9.9.
All eight CVEs affect Ivanti Neurons for ITSM versions prior to 2026.2, including on-premises deployments from 2025.2 through 2026.1. Cloud and SaaS customers were reportedly protected, with fixes already applied across cloud landscapes as of 9 August 2026. Mitigation centres on applying the September 2026 security patches for the relevant on-premise versions (2025.2, 2025.3, 2025.4, or 2026.1), with 2026.2 for on-premises due later on 21 September 2026.
Ivanti notes the risk is reduced for internet‑air-gapped deployments; as an interim measure, isolating the ITSM instance behind a firewall or VPN may help. Evidence of exploitation in the wild is not reported, and there is no public PoC at disclosure.