Junglewise Threat Intelligence

CVE-2026-12648: Ivanti Neurons for ITSM deserialization of untrusted data

CVE-2026-12648 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Ivanti Neurons for ITSM. Vendors: Ivanti.

Executive brief

Ivanti Neurons for ITSM is a service management platform used by organizations to manage IT incidents and requests. A deserialization vulnerability allows authenticated users to execute arbitrary code on the server, potentially compromising the entire platform and exposing sensitive organizational data including customer incidents and IT infrastructure information.

Technical details

This vulnerability is a deserialization of untrusted data flaw in Ivanti Neurons for ITSM versions before 2026.2. The vulnerability requires an authenticated attacker with network access to the affected service. By sending specially crafted serialized data, an attacker can execute arbitrary code on the server with the privileges of the application. The attack vector is network-based but requires valid authentication credentials. Patches are available in version 2026.2 and later.

Affected products

  • Ivanti Neurons for ITSM before 2026.2

Timeline

  • 2026-09-08: disclosed

References

Related threats