CVE-2026-12650: Critical severity Ivanti Neurons for ITSM vulnerability
Published Sep 8, 2026
·Updated
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Affected Software
1 affected component
Ivanti Neurons for ITSM<2026.2
Event History
Sep 8, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker must be authenticated to exploit the vulnerability. No user interaction is required.
2
What is the potential impact of successful exploitation?
An authenticated remote attacker can execute arbitrary code on the affected server, with high impact to confidentiality, integrity, and availability.
3
Which deployments are affected?
Ivanti Neurons for ITSM versions before 2026.2 are affected. The provided information does not state whether any particular default configuration changes exposure.