Description
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Published: 2026-09-08
Score: 9.9 Critical
EPSS: 1.6% Low
KEV: No
Impact: Remote Code Execution
Action: Patch ASAP
AI Analysis

Impact

A deserialization flaw in Ivanti Neurons for ITSM allows a remote authenticated attacker to execute arbitrary code on the server. The vulnerability stems from processing untrusted data without proper validation, which satisfies CWE‑502. If exploited, the attacker can gain full control over the application server and any underlying operating system resources, leading to complete compromise of the ITSM infrastructure.

Affected Systems

All installations of Ivanti Neurons for ITSM released before version 2026.2 are impacted. This includes any deployment of the product where users have authenticated access to the service.

Risk and Exploitability

The CVSS score is 9.9, indicating a critical severity. Because EPSS score is 1.46% and the vulnerability is not listed in CISA KEV, the precise exploitation probability cannot be quantified from the public data. The attack requires an authenticated session, so privilege escalation to an account with sufficient rights is necessary, but the impact is local to the server where the service runs. If successful, the attacker can achieve full code execution and compromise confidentiality, integrity, and availability of the system.

Generated by OpenCVE AI on September 10, 2026 at 03:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Ivanti Neurons for ITSM v2026.2 or later to eliminate the vulnerable deserialization path.
  • If an upgrade is not immediately possible, restrict external network access to the Neurons for ITSM server and enforce least‑privilege role‑based access controls.
  • Apply any interim security patches released by Ivanti and verify that all deserialization APIs handling untrusted data are disabled or removed.

Generated by OpenCVE AI on September 10, 2026 at 03:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ivanti:neurons_for_itsm:2025.2:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_itsm:2025.3:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_itsm:2025.4:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_itsm:2026.1:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_itsm:2026.2:*:*:*:*:*:*:*

Thu, 10 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Deserialization in Ivanti Neurons for ITSM

Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Deserialization in Ivanti Neurons for ITSM

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ivanti
Ivanti neurons For Itsm
Vendors & Products Ivanti
Ivanti neurons For Itsm

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ivanti Neurons For Itsm
cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-09-09T04:26:44.414Z

Reserved: 2026-06-18T18:25:49.156Z

Link: CVE-2026-12650

cve-icon Vulnrichment

Updated: 2026-09-08T15:21:02.605Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T15:18:40.850

Modified: 2026-09-18T18:07:30.283

Link: CVE-2026-12650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:45:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data