CVE-2026-12745: Critical severity Ivanti Neurons for ITSM vulnerability
Published Sep 8, 2026
·Updated
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
Affected Software
1 affected component
Ivanti Neurons for ITSM<2026.2
Event History
Sep 8, 2026
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated account or user interaction?
No. The vulnerability can be exploited remotely by an unauthenticated attacker and does not require user interaction.
2
Which deployments are affected?
Ivanti Neurons for ITSM versions before 2026.2 are affected. Successful exploitation can result in arbitrary code execution on the server.