Junglewise Threat Intelligence

CVE-2026-12744: Ivanti Neurons for ITSM deserialization remote code execution

CVE-2026-12744 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Technologies: Ivanti Neurons for ITSM. Vendors: Ivanti.

Executive brief

Ivanti Neurons for ITSM is an IT service management platform used by organizations to manage incidents, requests, and IT operations. A critical flaw in versions before 2026.2 allows attackers to send specially crafted requests that cause the server to execute arbitrary code without authentication, potentially compromising the entire IT service management system and the data it handles.

Technical details

The vulnerability is a deserialization of untrusted data flaw that enables remote code execution. An unauthenticated attacker can send maliciously crafted serialized objects to the Ivanti Neurons for ITSM server, which will deserialize and execute the attacker-controlled code with server privileges. No authentication or user interaction is required; the attack is exploitable over the network. This allows complete compromise of the affected system, including data theft, service disruption, and lateral movement within an organization's infrastructure.

Affected products

  • Ivanti Neurons for ITSM before 2026.2

Timeline

  • 2026-09-08: disclosed

References

Related threats