CVE-2026-12650

9.9

Ivanti · Neurons for ITSM

A deserialization of untrusted data vulnerability in Ivanti Neurons for ITSM allows a remote authenticated attacker to achieve arbitrary code execution on the server.

Executive summary

A critical deserialization vulnerability in Ivanti Neurons for ITSM allows authenticated remote attackers to achieve full system compromise.

Vulnerability

This is a deserialization of untrusted data flaw (CWE-502) that can be triggered by a remote authenticated attacker. By sending specially crafted serialized objects to the application, an attacker can execute arbitrary code on the underlying server.

Business impact

The potential for remote code execution represents a critical threat to business continuity and data integrity. A successful exploit grants the attacker total control over the server, which could lead to unauthorized access to sensitive internal data, complete system takeover, and significant reputational damage. Given the CVSS score of 9.9, this vulnerability is considered an extreme risk that requires immediate remediation.

Remediation

Immediate Action: Update Ivanti Neurons for ITSM to version 2026.2 or later to apply the necessary security patches.

Proactive Monitoring: Monitor server logs for unusual deserialization activities or unexpected process execution spawned by the application service.

Compensating Controls: Ensure that access to the management interface is restricted to authorized personnel only, as the vulnerability requires authenticated access to trigger.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The extreme severity of this vulnerability, combined with the potential for total system compromise, necessitates prompt action. Organizations should prioritize updating their Ivanti Neurons for ITSM instances to version 2026.2 immediately. Failure to patch this vulnerability leaves the environment exposed to attackers capable of leveraging valid credentials to execute arbitrary code.

More Ivanti CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources