IVANTI has released security updates across three enterprise products—Neurons for ITSM, Sentry and Endpoint Manager Mobile (EPMM)—to address a set of critical and high-severity flaws. Neurons for ITSM accounts for the bulk of the fixes, with eight identified bugs. Six are rated critical and could permit remote code execution.
The exploited-existence by authentication is only possible for CVE-2026-12744 and CVE-2026-12745, while the others involve missing authorisation (CVE-2026-12647, CVE-2026-12645, CVE-2026-12646) and deserialisation of untrusted data (CVE-2026-12650, CVE-2026-12744, CVE-2026-12745, CVE-2026-12651, CVE-2026-12648). Ivanti states that the September 2026 security updates fix these issues for Neurons for ITSM versions 2025.2, 2025.3, 2025.4 and 2026.1, with fixes also planned for version 2026.2 due on 21 September. On-premises deployments are urged to update to a resolved version.
Separately, Ivanti patched Sentry for a high-severity authentication-bypass flaw (CVE-2026-83527) affecting remote, unauthenticated attackers gaining admin privileges; fixed in Sentry versions R10.8.2, R10.7.3 and R10.6.4. EPMM addressed another high-severity authentication-bypass (CVE-2026-18851) requiring authentication to exploit; fixes appear in EPMM versions 12.10.0[.]0, 12.9.0[.]2 and 12.8.0[.]4. Ivanti says it is not aware of any of these vulnerabilities being exploited in the wild. No other Ivanti products are affected.