Executive brief
Ivanti Neurons for ITSM is a cloud-based IT service management platform used by organizations to manage IT incidents, requests, and assets. A deserialization vulnerability allows authenticated remote attackers to execute arbitrary code on the server, potentially compromising the confidentiality, integrity, and availability of all IT service management data and operations.
Technical details
This vulnerability exists in Ivanti Neurons for ITSM versions before 2026.2 and involves insecure deserialization of untrusted data. The flaw allows a remote authenticated attacker to craft and send malicious serialized objects that execute arbitrary code with server privileges when deserialized. The vulnerability requires existing authentication credentials to exploit, limiting exposure to authenticated users. An attacker with valid credentials can achieve complete remote code execution on the affected server. Ivanti has released a patch in version 2026.2 and later.
Affected products
- Ivanti Neurons for ITSM before 2026.2
Timeline
- 2026-09-08: disclosed