Description
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Published: 2026-09-08
Score: 8.8 High
EPSS: 1.5% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A deserialization flaw in Ivanti Neurons for ITSM allows an attacker who is already authenticated to the system to execute arbitrary code. The vulnerability is caused by untrusted input being deserialized without proper validation, which is a classic insecure deserialization weakness. If exploited, the attacker could gain control of the application server, manipulate data, and potentially access or exfiltrate sensitive information.

Affected Systems

All installations of Ivanti Neurons for ITSM before version 2026.2 are affected. The vulnerability targets the server component that processes user data, and only clients that can authenticate to the system can trigger the flaw.

Risk and Exploitability

The CVSS score of 8.8 classifies this as High severity. The EPSS score is 1%, indicating a low but present exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote authenticated attack using valid credentials. The attacker must first obtain legitimate access to the system, after which arbitrary code execution can be achieved, but the CVE description does not specify whether higher privileges are required.

Generated by OpenCVE AI on September 10, 2026 at 03:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade or patch Ivanti Neurons for ITSM to version 2026.2 or later, which removes the unsafe deserialization path.
  • Restrict authentication to trusted accounts and enforce strong password or MFA policies to reduce the risk of an attacker gaining credentials.
  • Apply network segmentation and firewall rules to limit external entities from reaching the Neurons for ITSM server, adding an extra barrier before any potential exploitation.

Generated by OpenCVE AI on September 10, 2026 at 03:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ivanti:neurons_for_itsm:2025.2:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_itsm:2025.3:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_itsm:2025.4:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_itsm:2026.1:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_itsm:2026.2:*:*:*:*:*:*:*

Thu, 10 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Title Untrusted Deserialization Allows Remote Authenticated Arbitrary Code Execution in Ivanti Neurons for ITSM

Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability Allowing Remote Code Execution in Ivanti Neurons for ITSM

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability Allowing Remote Code Execution in Ivanti Neurons for ITSM
First Time appeared Ivanti
Ivanti neurons For Itsm
Vendors & Products Ivanti
Ivanti neurons For Itsm

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ivanti Neurons For Itsm
cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-09-09T04:26:46.078Z

Reserved: 2026-06-18T18:25:47.315Z

Link: CVE-2026-12648

cve-icon Vulnrichment

Updated: 2026-09-08T15:20:45.800Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T15:18:40.733

Modified: 2026-09-18T18:05:15.220

Link: CVE-2026-12648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:15:16Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data