Impact
Ivanti Neurons for ITSM contains a deserialization flaw that allows an unauthenticated attacker to send crafted binary data to the server. The vulnerability is triggered when the application processes untrusted serialized input, leading to arbitrary code execution on the host. The flaw is characterized as a high‑severity deserialization issue under CWE‑502.
Affected Systems
Ivanti Neurons for ITSM versions prior to 2026.2 are vulnerable. The issue applies to all deployments using those releases and affects the server component that handles incoming serialized data.
Risk and Exploitability
With a CVSS score of 9.8, this flaw represents an extremely high risk. Exploitation requires only network access to the server and no authentication, making it remotely accessible to any actor who can reach the exposed endpoint. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog, but the high severity and unauthenticated nature mean it should be treated as a critical security risk.
OpenCVE Enrichment