Executive brief
Ivanti Neurons for ITSM is an IT service management platform used by organizations to manage IT operations and incidents. A flaw in how the application processes untrusted data allows remote attackers to execute arbitrary code without authentication, potentially giving them complete control over the server and access to all managed systems and data.
Technical details
This is a deserialization of untrusted data vulnerability (CWE-502) in Ivanti Neurons for ITSM versions before 2026.2. The vulnerability allows a remote, unauthenticated attacker to send specially crafted serialized data to the server, which is deserialized without proper validation. This enables arbitrary code execution with the privileges of the application server. The attack is network-accessible and requires no prior authentication or user interaction. Organizations using affected versions should immediately update to 2026.2 or later.
Affected products
- Ivanti Neurons for ITSM before 2026.2
Timeline
- 2026-09-08: disclosed