Ivanti has released a broad set of security advisories covering ten vulnerabilities in Endpoint Manager Mobile, Neurons for ITSM and Sentry. The most serious flaws can allow unauthenticated remote code execution, while others permit administrative access or code execution after an attacker gains a lower level of authentication.
The disclosures affect systems that occupy highly trusted positions in enterprise environments. Mobile management and IT service platforms commonly hold device information, credentials and administrative workflows, so a successful compromise could provide a powerful base for further intrusion. Ivanti says it had not seen evidence of exploitation before disclosure, but the severity and exposure of these products support prompt remediation.
Neurons for ITSM carries the most critical risks
Eight of the CVEs affect Ivanti Neurons for ITSM. CVE-2026-12744 and CVE-2026-12745 are deserialization vulnerabilities with CVSS scores of 9.8. Both can be reached by an unauthenticated attacker and may lead to arbitrary code execution on the server, making internet-accessible on-premises deployments particularly urgent.
Three additional deserialization issues—CVE-2026-12651, CVE-2026-12650 and CVE-2026-12648—require authentication but can still enable remote code execution. Three missing-authorization flaws, CVE-2026-12645, CVE-2026-12646 and CVE-2026-12647, also allow authenticated code execution and carry maximum or near-maximum severity ratings of 9.9.
Ivanti credited advanced large language models used in its product security and engineering work with helping uncover the ITSM flaws. That detail is unusual in a formal advisory, but it does not change the operational response: customers need to determine which deployment model and version they run, then confirm the appropriate fix has been applied.
Ivanti patched its cloud and software-as-a-service ITSM environments on August 9, with no customer action required. On-premises installations on versions 2025.2 through 2026.1 require the September 2026 security patches. The company plans to release on-premises version 2026.2 on September 21, but exposed customers should not delay available remediation while waiting for a later feature release.
EPMM flaw can elevate users to full administrator
CVE-2026-18851 affects Ivanti Endpoint Manager Mobile and is rated 8.8. The missing-authorization weakness lets a remote authenticated attacker elevate privileges to full administrator access. Affected releases include 12.9.0.1 and earlier, 12.8.0.3 and earlier, and all versions before 12.10.0.0.
Fixed versions are 12.10.0.0, 12.9.0.2 and 12.8.0.4. Because exploitation needs an authenticated account, defenders should not assume the risk is low: stolen credentials or a compromised low-privilege user can supply the starting access, after which full administrative control may expose managed devices and configuration data.
Sentry authentication bypass grants administrative access
The final issue, CVE-2026-83527, affects Ivanti Sentry systems managed through EPMM and Neurons for MDM. Rated 8.1, the authentication bypass can let a remote unauthenticated attacker obtain administrator-level access. Ivanti has provided fixes in Sentry releases R10.8.2, R10.7.3 and R10.6.4.
Although this score is lower than the critical ITSM vulnerabilities, lack of an authentication requirement makes exposure important. Teams should check management interfaces, network placement and logs for unexpected administrative sessions while deploying the update.
Priorities for administrators
- Identify every EPMM, Neurons for ITSM and Sentry instance, including disaster-recovery systems.
- Patch internet-facing on-premises ITSM servers first, especially versions affected by unauthenticated RCE.
- Upgrade EPMM and Sentry to the fixed maintenance releases listed by Ivanti.
- Review recent account creation, privilege changes, configuration exports and unusual server processes.
- Restrict management interfaces to trusted networks and require strong multifactor authentication.
There is no reported active exploitation at publication time, but historical attacker interest in Ivanti infrastructure means defenders should not treat that as a reason to postpone. Patching should be paired with log review and exposure reduction, since an update prevents future exploitation but cannot reveal whether an earlier compromise already occurred. Organizations should document their installed versions and remediation evidence so incident responders can quickly distinguish vulnerable systems from confirmed-clean, updated assets.
Leave a Reply
You must be logged in to post a comment.