2026-09-11 · view entry permalink →
Ivanti September 2026 Security Update, ten CVEs across Neurons for ITSM, Sentry and EPMM, two unauthenticated CVSS 9.8 deserialization RCEs
Ivanti's 2026-09-08 security update discloses ten CVEs across three product lines, none reported exploited (Ivanti, 2026-09-08). Neurons for ITSM carries the most severe pair: CVE-2026-12744 and CVE-2026-12745, both CVSS 9.8 unauthenticated deserialization-of-untrusted-data flaws reaching remote code execution on the server with no credentials and no user interaction (SecurityWeek, 2026-09-09). Six further ITSM flaws need low-privilege authentication first: three missing-authorization bugs (CVE-2026-12645/12646/12647, CVSS 9.9) and three further deserialization paths (CVE-2026-12650 at 9.9, CVE-2026-12651/12648 at 8.8) all escalate an authenticated low-privilege session to code execution or full administrative control (SecurityWeek, 2026-09-09; Cyber Security News, 2026-09-08). Ivanti Sentry carries CVE-2026-83527 (CVSS 8.1), a high-attack-complexity authentication bypass that lets a remote unauthenticated attacker obtain administrative access to the Sentry platform (NCSC-NL NCSC-2026-0357, 2026-09-09). Ivanti Endpoint Manager Mobile carries CVE-2026-18851 (CVSS 8.8), a missing-authorization flaw letting an authenticated low-privilege user escalate to full administrator (NCSC-NL NCSC-2026-0359, 2026-09-09).
The September patch covers on-premises Neurons for ITSM versions 2025.2, 2025.3, 2025.4 and 2026.1; the fixes are also included in the 2026.2 release line, scheduled for 2026-09-21 (SecurityWeek, 2026-09-09). NCSC-NL's advisory additionally lists the Cloud/SaaS edition of Neurons for ITSM as affected, without stating a separate cloud remediation date (NCSC-NL NCSC-2026-0358, 2026-09-09). Sentry is fixed in R10.8.2/R10.7.3/R10.6.4, EPMM in 12.10.0.0/12.9.0.2/12.8.0.4 (SecurityWeek, 2026-09-09). Ivanti states it has no evidence of exploitation for any of the ten and that no other Ivanti product is affected (Ivanti, 2026-09-08). Notably, Ivanti states it has integrated multiple advanced large language models into its product-security and engineering workflows to identify vulnerabilities "especially those that are difficult to identify with traditional tooling, such as SAST and DAST," and credits this with surfacing some of the flaws disclosed today (Ivanti, 2026-09-08); a rare instance of AI-assisted vulnerability discovery being credited directly in a formal vendor advisory (Cyber Security News, 2026-09-08).
We have no evidence of these vulnerabilities being exploited in the wild.
These vulnerabilities do not impact any other Ivanti solutions.
these ITSM flaws were uncovered through the company's use of advanced large language models integrated into its product security and engineering workflows, marking a rare instance of AI-assisted vulnerability discovery being credited in a formal advisory.
According to Ivanti's advisory, only CVE-2026-12744 and CVE-2026-12745 can be exploited without authentication.