Description
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
Published: 2026-09-08
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Ivanti Neurons for ITSM contains a deserialization flaw that allows an unauthenticated attacker to send crafted binary data to the server. The vulnerability is triggered when the application processes untrusted serialized input, leading to arbitrary code execution on the host. The flaw is characterized as a high‑severity deserialization issue under CWE‑502.

Affected Systems

Ivanti Neurons for ITSM versions prior to 2026.2 are vulnerable. The issue applies to all deployments using those releases and affects the server component that handles incoming serialized data.

Risk and Exploitability

With a CVSS score of 9.8, this flaw represents an extremely high risk. Exploitation requires only network access to the server and no authentication, making it remotely accessible to any actor who can reach the exposed endpoint. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog, but the high severity and unauthenticated nature mean it should be treated as a critical security risk.

Generated by OpenCVE AI on September 8, 2026 at 15:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Ivanti Neurons for ITSM to version 2026.2 or later, which contains the fix for the deserialization issue.
  • Restrict network access to the Neurons server so that only trusted IP ranges can communicate with it, mitigating the ability of unauthenticated attackers to reach the vulnerable endpoint.
  • Enable application-layer logging or intrusion detection to flag attempts to send malformed serialized data, helping to detect and respond to exploitation attempts.

Generated by OpenCVE AI on September 8, 2026 at 15:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Deserialization in Ivanti Neurons for ITSM
First Time appeared Ivanti
Ivanti neurons For Itsm
Vendors & Products Ivanti
Ivanti neurons For Itsm

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ivanti Neurons For Itsm
cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-09-08T15:22:05.615Z

Reserved: 2026-06-19T17:34:04.843Z

Link: CVE-2026-12744

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-08T15:18:41.080

Modified: 2026-09-08T15:28:33.090

Link: CVE-2026-12744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:30:18Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data