CTIPilot
← Back to the live brief
HIGHCVE-2026-12744 +9NATOA2vulnerability

Ivanti September 2026 Security Update, ten CVEs across Neurons for ITSM, Sentry and EPMM, two unauthenticated CVSS 9.8 deserialization RCEs

Ivanti discloses two unauthenticated pre-auth RCEs in Neurons for ITSM, crediting LLM-assisted review with surfacing several of the disclosed flaws

Defender actions

  • Patch Ivanti Neurons for ITSM to the September 2026 release now; CVE-2026-12744 and CVE-2026-12745 are unauthenticated, no-interaction deserialization flaws reaching full remote code execution on any internet-exposed instance.

Analysis

Ivanti's 2026-09-08 security update discloses ten CVEs across three product lines, none reported exploited (Ivanti, 2026-09-08). Neurons for ITSM carries the most severe pair: CVE-2026-12744 and CVE-2026-12745, both CVSS 9.8 unauthenticated deserialization-of-untrusted-data flaws reaching remote code execution on the server with no credentials and no user interaction (SecurityWeek, 2026-09-09). Six further ITSM flaws need low-privilege authentication first: three missing-authorization bugs (CVE-2026-12645/12646/12647, CVSS 9.9) and three further deserialization paths (CVE-2026-12650 at 9.9, CVE-2026-12651/12648 at 8.8) all escalate an authenticated low-privilege session to code execution or full administrative control (SecurityWeek, 2026-09-09; Cyber Security News, 2026-09-08). Ivanti Sentry carries CVE-2026-83527 (CVSS 8.1), a high-attack-complexity authentication bypass that lets a remote unauthenticated attacker obtain administrative access to the Sentry platform (NCSC-NL NCSC-2026-0357, 2026-09-09). Ivanti Endpoint Manager Mobile carries CVE-2026-18851 (CVSS 8.8), a missing-authorization flaw letting an authenticated low-privilege user escalate to full administrator (NCSC-NL NCSC-2026-0359, 2026-09-09).

The September patch covers on-premises Neurons for ITSM versions 2025.2, 2025.3, 2025.4 and 2026.1; the fixes are also included in the 2026.2 release line, scheduled for 2026-09-21 (SecurityWeek, 2026-09-09). NCSC-NL's advisory additionally lists the Cloud/SaaS edition of Neurons for ITSM as affected, without stating a separate cloud remediation date (NCSC-NL NCSC-2026-0358, 2026-09-09). Sentry is fixed in R10.8.2/R10.7.3/R10.6.4, EPMM in 12.10.0.0/12.9.0.2/12.8.0.4 (SecurityWeek, 2026-09-09). Ivanti states it has no evidence of exploitation for any of the ten and that no other Ivanti product is affected (Ivanti, 2026-09-08). Notably, Ivanti states it has integrated multiple advanced large language models into its product-security and engineering workflows to identify vulnerabilities "especially those that are difficult to identify with traditional tooling, such as SAST and DAST," and credits this with surfacing some of the flaws disclosed today (Ivanti, 2026-09-08); a rare instance of AI-assisted vulnerability discovery being credited directly in a formal vendor advisory (Cyber Security News, 2026-09-08).

Cited evidence

We have no evidence of these vulnerabilities being exploited in the wild.

These vulnerabilities do not impact any other Ivanti solutions.

Ivanti

these ITSM flaws were uncovered through the company's use of advanced large language models integrated into its product security and engineering workflows, marking a rare instance of AI-assisted vulnerability discovery being credited in a formal advisory.

Cyber Security News 2026-09-08

According to Ivanti's advisory, only CVE-2026-12744 and CVE-2026-12745 can be exploited without authentication.

SecurityWeek 2026-09-09

Sources6

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.