CTIPilot

Ivanti Neurons for ITSM, authenticated missing-authorization escalation to RCE (CVSS 9.9)

cve · CVE-2026-12645

Coverage timeline
1
first 2026-09-11 → last 2026-09-11
Peak priority
high
1 high
Sources cited
6
4 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-11/ivanti-september-2026-security-update-itsm-sentry-epmm · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-09-11/ivanti-september-2026-security-update-itsm-sentry-epmm · ATT&CK page ↗

Story timeline

  1. 2026-09-11Ivanti September 2026 Security Update, ten CVEs across Neurons for ITSM, Sentry and EPMM, two unauthenticated CVSS 9.8 deserialization RCEs
    trending-vulnerabilitiesIvanti discloses two unauthenticated pre-auth RCEs in Neurons for ITSM, crediting LLM-assisted review with surfacing several of the disclosed flaws

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • advisories.ncsc.nl3 (50%)
  • cybersecuritynews.com1 (17%)
  • ivanti.com1 (17%)
  • securityweek.com1 (17%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Ivanti Neurons for ITSM, authenticated missing-authorization escalation to RCE (CVSS 9.9) (1)

2026-09-11 · view entry permalink →

Ivanti September 2026 Security Update, ten CVEs across Neurons for ITSM, Sentry and EPMM, two unauthenticated CVSS 9.8 deserialization RCEs

Ivanti's 2026-09-08 security update discloses ten CVEs across three product lines, none reported exploited (Ivanti, 2026-09-08). Neurons for ITSM carries the most severe pair: CVE-2026-12744 and CVE-2026-12745, both CVSS 9.8 unauthenticated deserialization-of-untrusted-data flaws reaching remote code execution on the server with no credentials and no user interaction (SecurityWeek, 2026-09-09). Six further ITSM flaws need low-privilege authentication first: three missing-authorization bugs (CVE-2026-12645/12646/12647, CVSS 9.9) and three further deserialization paths (CVE-2026-12650 at 9.9, CVE-2026-12651/12648 at 8.8) all escalate an authenticated low-privilege session to code execution or full administrative control (SecurityWeek, 2026-09-09; Cyber Security News, 2026-09-08). Ivanti Sentry carries CVE-2026-83527 (CVSS 8.1), a high-attack-complexity authentication bypass that lets a remote unauthenticated attacker obtain administrative access to the Sentry platform (NCSC-NL NCSC-2026-0357, 2026-09-09). Ivanti Endpoint Manager Mobile carries CVE-2026-18851 (CVSS 8.8), a missing-authorization flaw letting an authenticated low-privilege user escalate to full administrator (NCSC-NL NCSC-2026-0359, 2026-09-09).

The September patch covers on-premises Neurons for ITSM versions 2025.2, 2025.3, 2025.4 and 2026.1; the fixes are also included in the 2026.2 release line, scheduled for 2026-09-21 (SecurityWeek, 2026-09-09). NCSC-NL's advisory additionally lists the Cloud/SaaS edition of Neurons for ITSM as affected, without stating a separate cloud remediation date (NCSC-NL NCSC-2026-0358, 2026-09-09). Sentry is fixed in R10.8.2/R10.7.3/R10.6.4, EPMM in 12.10.0.0/12.9.0.2/12.8.0.4 (SecurityWeek, 2026-09-09). Ivanti states it has no evidence of exploitation for any of the ten and that no other Ivanti product is affected (Ivanti, 2026-09-08). Notably, Ivanti states it has integrated multiple advanced large language models into its product-security and engineering workflows to identify vulnerabilities "especially those that are difficult to identify with traditional tooling, such as SAST and DAST," and credits this with surfacing some of the flaws disclosed today (Ivanti, 2026-09-08); a rare instance of AI-assisted vulnerability discovery being credited directly in a formal vendor advisory (Cyber Security News, 2026-09-08).

We have no evidence of these vulnerabilities being exploited in the wild.

These vulnerabilities do not impact any other Ivanti solutions.

Ivanti

these ITSM flaws were uncovered through the company's use of advanced large language models integrated into its product security and engineering workflows, marking a rare instance of AI-assisted vulnerability discovery being credited in a formal advisory.

Cyber Security News 2026-09-08

According to Ivanti's advisory, only CVE-2026-12744 and CVE-2026-12745 can be exploited without authentication.

SecurityWeek 2026-09-09
vulnerability11 Sep 04:35Zmulti-sourceOpen finding ↗