Back to Feed
VulnerabilitiesSep 9, 2026

Ivanti Patches Critical Flaws Across Enterprise Security Products

Ivanti patches critical RCE and auth bypass flaws in Neurons for ITSM, Sentry, and EPMM.

Summary

Ivanti has released security updates addressing six critical and two high-severity vulnerabilities in its Neurons for ITSM product, with some allowing for remote code execution. Additionally, critical authentication bypass flaws were patched in Sentry and EPMM. The company stated it is unaware of any active exploitation in the wild.

Full text

Ivanti on Tuesday announced security updates that address vulnerabilities rated critical and high severity in its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) products. Neurons for ITSM received fixes for the largest number of security defects. Of the eight bugs, six are critical-severity issues that could lead to remote code execution, Ivanti warns. These include CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646 (CVSS score of 9.9/10), described as missing authorization issues; and CVE-2026-12650 (CVSS score of 9.9/10), CVE-2026-12744, and CVE-2026-12745 (CVSS score of 9.8/10), described as deserialization of untrusted data weaknesses. The remaining two bugs, tracked as CVE-2026-12651 and CVE-2026-12648, are high-severity deserialization of untrusted data defects also leading to remote code execution. According to Ivanti’s advisory, only CVE-2026-12744 and CVE-2026-12745 can be exploited without authentication. All vulnerabilities were addressed with the September 2026 security updates rolled out for Neurons for ITSM versions 2025.2, 2025.3, 2025.4, and 2026.1. The fixes will also be included in version 2026.2 of the product, scheduled for September 21.Advertisement. Scroll to continue reading. “Customers using the on-premises version of Ivanti Neurons for ITSM should update their solution to one of the resolved versions to address the vulnerabilities,” Ivanti notes. On Tuesday, Ivanti released Sentry versions R10.8.2, R10.7.3, and R10.6.4 with patches for CVE-2026-83527, a high-severity authentication bypass that could allow remote, unauthenticated attackers to gain administrative privileges. EPMM versions 12.10.0.0, 12.9.0.2, and 12.8.0.4 were released on Tuesday to resolve CVE-2026-18851, another high-severity authentication bypass. Unlike the Sentry bug, this one requires authentication for successful exploitation. Ivanti says it is not aware of any of these vulnerabilities being exploited in the wild. No other Ivanti products are affected, the company notes. Also on Tuesday, Citrix announced fixes for two medium-severity flaws in its Workspace app for Windows: an out-of-bounds read that requires local access, and an out-of-bounds write that requires physical access to an affected system. Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day Related: N-able Patches Critical Zero-Day in N-central Related: 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire SAP Patches Critical Extended Passport Processing VulnerabilityMikroTik Patches Critical Flaws Chained to Hack RoutersMathspace Data Breach Exposes Over 1 Million PeopleN-able Patches Critical Zero-Day in N-centralNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day ExploitsNorth Korean Hackers Deploy New Linux Espionage ToolkitAdobe Commerce Zero-Day Exploited to Backdoor Online StoresModified ScreenConnect Clients Used in Worm-Like Campaign Latest News ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical FlawsNew Phishing Attack Creates Malicious Pages Inside the Victim’s BrowserThis Key Will Self-Destruct: An Open Standard for Revocable API KeysChrome 153 Patches Seventh Zero-Day of 2026Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-DaysAdobe Patches Over 170 Vulnerabilities, Including Commerce Zero-DayThe Hidden Instructions That Can Hijack AI AgentsHackers Return $263 Million Stolen From Liquid Network Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-12647
  • cve — CVE-2026-12645
  • cve — CVE-2026-12646
  • cve — CVE-2026-12650
  • cve — CVE-2026-12744
  • cve — CVE-2026-12745
  • cve — CVE-2026-12651
  • cve — CVE-2026-12648
  • cve — CVE-2026-83527
  • cve — CVE-2026-18851

Entities

Ivanti (vendor)Neurons for ITSM (product)Sentry (product)Endpoint Manager Mobile (EPMM) (product)