Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Ivanti Patches Nine Critical Flaws Across EPMM, Neurons for ITSM, and Sentry
Ivanti Patches Nine Critical Flaws Across EPMM, Neurons for ITSM, and Sentry
Read Time:3 Minute, 52 Second

Ivanti has published a wave of security advisories covering three flagship enterprise products — Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry — disclosing nine distinct vulnerabilities, several of which carry near-maximum severity scores and allow unauthenticated attackers to execute arbitrary code. While Ivanti says it has no evidence of active exploitation for any of these flaws yet, the company’s products have repeatedly become high-priority targets for both ransomware crews and nation-state actors within weeks of similar disclosures in the past.

EPMM: Authenticated Privilege Escalation to Full Admin

The mobile device management platform is affected by CVE-2026-18851, a missing-authorization flaw (CWE-862) carrying a CVSS score of 8.8. An attacker who already holds any authenticated account on the system can exploit the bug to escalate privileges all the way to full administrator, at which point they could reconfigure device policies, push malicious profiles, or access sensitive fleet data across every managed endpoint. The flaw affects EPMM builds 12.9.0.1 and earlier and 12.8.0.3 and earlier; Ivanti has shipped fixes in versions 12.10.0.0, 12.9.0.2, and 12.8.0.4.

Neurons for ITSM: The Most Severe Cluster

The IT service management platform carries the heaviest concentration of critical bugs in this release. Two deserialization-of-untrusted-data flaws, CVE-2026-12744 and CVE-2026-12745 (CWE-502), score 9.8 and allow a completely unauthenticated attacker to execute arbitrary code on the server — no login credentials of any kind required. Three additional missing-authorization vulnerabilities, CVE-2026-12645, CVE-2026-12646, and CVE-2026-12647, score even higher at 9.9 and let an authenticated attacker execute arbitrary code, effectively turning a low-privilege account into full server compromise.

Rounding out the ITSM advisory are three further deserialization issues — CVE-2026-12651, CVE-2026-12650, and CVE-2026-12648 — which also enable remote code execution for authenticated users, though at somewhat lower severity than the unauthenticated pair. Notably, Ivanti’s advisory credits large language models used in its product security workflows with helping identify several of these ITSM flaws, something the company itself flagged as a rare public instance of AI-assisted vulnerability discovery being formally acknowledged in a security bulletin.

Patch timing differs by deployment model: cloud and SaaS customers were already protected as of August 9, 2026, with no action required on their end. On-premises customers running versions 2025.2 through 2026.1 need to apply the September 2026 security patches manually, and Ivanti has scheduled a dedicated on-premises release, version 2026.2, for September 21, 2026.

Sentry: Authentication Bypass to Admin Access

Ivanti Sentry, which handles secure gateway access for devices managed through EPMM and Neurons for MDM, is affected by CVE-2026-83527, an authentication-bypass flaw (CWE-288) scoring 8.1. A remote, unauthenticated attacker can exploit it to gain administrative-level access to the Sentry deployment outright. The issue was responsibly disclosed by a researcher going by “btaol” of Aquila Sec Lab. Fixed versions are R10.8.2, R10.7.3, and R10.6.4.

Why Ivanti Disclosures Warrant Fast Action

None of the nine vulnerabilities in this batch are currently listed as under active exploitation, but that track record shouldn’t offer much comfort to defenders. Ivanti’s edge and mobile management products — EPMM in particular, formerly known as MobileIron — have a documented history of being targeted by sophisticated attackers, including state-linked groups, within a short window after vulnerability details become public. That pattern has held across multiple prior Ivanti disclosures, and unauthenticated, deserialization-based RCE bugs like the ones affecting Neurons for ITSM are exactly the type of flaw that tends to get weaponized fastest once technical details or proof-of-concept code begin circulating.

Security teams running any of the affected products should treat this as a priority patching cycle rather than routine maintenance:

  • Upgrade EPMM to 12.10.0.0, 12.9.0.2, or 12.8.0.4 as soon as possible
  • Apply the September 2026 patches to on-premises Neurons for ITSM deployments now rather than waiting for the September 21 release, given the severity of the unauthenticated RCE bugs
  • Upgrade Sentry to R10.8.2, R10.7.3, or R10.6.4
  • Review authentication and access logs on all three platforms for signs of unusual privilege changes or administrative actions predating the patch

With enterprise mobility and IT service management platforms sitting at the center of how organizations manage their entire device fleet, a compromise of any one of these systems can cascade quickly — making early patching far cheaper than incident response after the fact.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Ivanti Patches Nine Critical Flaws Across EPMM, Neurons for ITSM, and Sentry, use the discussion on Forum.

>> forum community

Comments

Leave a Reply