【Security Vulnerability Alert】Ivanti Neurons for ITSM contains 8 high-risk security vulnerabilities

 
2026/9/22 ~ 2027/3/22
View Count:20

Forwarded from Taiwan Computer Emergency Response Team / Coordination Center Security Information Alert TWCERTCC-200-202609-00000010

[Content Description]
ITSM is a reliable and powerful IT service management solution under Ivanti, which can help organizations improve service efficiency and ensure IT operations compliance and security. Recently, a major security advisory was issued for Ivanti Neurons for ITSM, and its product contains 8 high-risk security vulnerabilities.
CVE-2026-12744 (CVSS:9.8) is an untrusted data deserialization vulnerability that allows an unauthenticated remote attacker to execute arbitrary code on the server.
CVE-2026-12745 (CVSS:9.8) is an untrusted data deserialization vulnerability that allows an unauthenticated remote attacker to execute arbitrary code on the server.
CVE-2026-12651 (CVSS:8.8) is an untrusted data deserialization vulnerability that allows an authenticated remote attacker to execute arbitrary code on the server.
CVE-2026-12650 (CVSS:9.9) is an untrusted data deserialization vulnerability that allows an authenticated remote attacker to execute arbitrary code on the server.
CVE-2026-12648 (CVSS:8.8) is an untrusted data deserialization vulnerability that allows an authenticated remote attacker to execute arbitrary code on the server.
CVE-2026-12645 (CVSS:9.9) is an authorization missing vulnerability that allows an authenticated remote attacker to execute arbitrary code on the server.
CVE-2026-12646 (CVSS:9.9) is an authorization missing vulnerability that allows an authenticated remote attacker to execute arbitrary code on the server.
CVE-2026-12647 (CVSS:9.9) is an authorization missing vulnerability that allows an authenticated remote attacker to execute arbitrary code on the server.

[Affected Platforms]
Ivanti Neurons for ITSM (Cloud / SaaS) version 2026.2
Ivanti Neurons for ITSM On-Prem versions 2025.2, 2025.3, 2025.4, 2026.1

[Recommended Measures]
Please update to the following versions:
Ivanti Neurons for ITSM (Cloud / SaaS) mo2026.2 (inclusive) and later versions
Ivanti Neurons for ITSM On-Prem 2025.2 Sept 2026 Security Patch
Ivanti Neurons for ITSM On-Prem2025.3 Sept 2026 Security Patch
Ivanti Neurons for ITSM On-Prem2025.4 Sept 2026 Security Patch
Ivanti Neurons for ITSM On-Prem2026.1 Sept 2026 Security Patch
Ivanti Neurons for ITSM On-Prem (inclusive) and later 2026.2 versions

[References]
1. https://www.twcert.org.tw/tw/cp-169-11192-fe339-1.html

Files
system_update_alt參考資料
Top↑