Executive brief
Ivanti Neurons for ITSM is a service management platform used by organizations to manage IT incidents and requests. A deserialization vulnerability allows authenticated users to execute arbitrary code on the server, potentially compromising the entire platform and exposing sensitive organizational data including customer incidents and IT infrastructure information.
Technical details
This vulnerability is a deserialization of untrusted data flaw in Ivanti Neurons for ITSM versions before 2026.2. The vulnerability requires an authenticated attacker with network access to the affected service. By sending specially crafted serialized data, an attacker can execute arbitrary code on the server with the privileges of the application. The attack vector is network-based but requires valid authentication credentials. Patches are available in version 2026.2 and later.
Affected products
- Ivanti Neurons for ITSM before 2026.2
Timeline
- 2026-09-08: disclosed