Junglewise Threat Intelligence

CVE-2026-12650: Ivanti Neurons for ITSM deserialization vulnerability

CVE-2026-12650 · Severity: critical · CVSS 9.9 · Published 2026-09-08

Technologies: Ivanti Neurons for ITSM. Vendors: Ivanti.

Executive brief

Ivanti Neurons for ITSM is a service management platform used by organizations to manage IT operations and support tickets. A flaw in how the system processes untrusted data allows authenticated attackers to execute arbitrary code on the server, potentially gaining complete control over the platform and compromising all data and operations managed through it.

Technical details

This vulnerability is a deserialization of untrusted data flaw in Ivanti Neurons for ITSM versions before 2026.2. The vulnerability allows a remote authenticated attacker to execute arbitrary code on the affected server. No authentication bypass is required—an attacker must already have valid credentials. The flaw stems from improper handling of serialized object input, enabling code execution with the privileges of the application server process.

Affected products

  • Ivanti Neurons for ITSM before 2026.2

Timeline

  • 2026-09-08: disclosed

References

Related threats