Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN874 _____________________________________________________________________ DATE : 09/09/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Ivanti Neurons for ITSM. ===================================================================== https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US _____________________________________________________________________ Security Advisory Ivanti Neurons for ITSM (Multiple CVEs) Primary Product Ivanti Neurons for ITSM (Premise) Article Type Security Advisory Created Date Sep 8, 2026 2:14:07 PM Last Modified Date Sep 8, 2026 2:14:07 PM Summary Ivanti has released updates for Ivanti Neurons for ITSM (N-ITSM) which addresses High and Critical severity vulnerabilities. We are not aware of any customers being exploited by these vulnerabilities at the time of disclosure. Additionally, it’s important for customers to know that these vulnerabilities were discovered as part of Ivanti’s use of advanced LLMs in discovering vulnerabilities that have previously been missed by traditional tools. Vulnerability Details: CVE Number Description CVSS Score (Severity) CVSS Vector CWE CVE-2026-12744 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. 9.8 (Critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CWE-502 CVE-2026-12745 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. 9.8 (Critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CWE-502 CVE-2026-12651 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. 8.8 (High) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CWE-502 CVE-2026-12650 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. 9.9 (Critical) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CWE-502 CVE-2026-12648 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. 8.8 (High) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CWE-502 CVE-2026-12645 A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. 9.9 (Critical) CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CWE-862 CVE-2026-12646 A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. 9.9 (Critical) CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CWE-862 CVE-2026-12647 A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. 9.9 (Critical) CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CWE-862 Affected Version Product Name Affected Version(s) Resolved Version(s) Patch Availability Ivanti Neurons for ITSM (Cloud / SaaS) 2026.2 mo2026.2 The fix was applied to all cloud landscapes on August 9, 2026 Ivanti Neurons for ITSM On-Prem 2025.2, 2025.3, 2025.4, 2026.1 2025.2 Sept 2026 Security Patch, 2025.3 Sept 2026 Security Patch, 2025.4 Sept 2026 Security Patch, 2026.1 Sept 2026 Security Patch, 2026.2 Download Available in ILS Solution Customers using the on-premises version of Ivanti Neurons for ITSM should update their solution to one of the resolved versions to address the vulnerabilities. Please note, version 2026.2 is a new version for on-premises and will be available on September 21. This new version will contain the fixes for these issues when it is released. Risk of exploitation of these vulnerabilities is significantly reduced for on-premises customers if Ivanti Neurons for ITSM is not exposed to the internet. No action is needed from customers using the Cloud / Saas version of Ivanti Neurons for ITMS as the fix was applied to all landscapes on August 9, 2026. FAQ Are you aware of any active exploitation of these vulnerabilities? We are not aware of any customers being exploited by these vulnerabilities prior to public disclosure. These vulnerabilities were discovered with Ivanti’s use of advanced LLM’s in our product security and engineering processes. How can I tell if I have been compromised? Currently, there is no known public exploitation of this vulnerability that could be used to provide a list of indicators of compromise. What should I do if I need help? If you have questions after reviewing this information, you can log a case and/or request a call via the Ivanti Innovators Hub. Article Number : 000108854 ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================