Ivanti has patched three critical vulnerabilities in Neurons for ITSM, the IT service desk software companies use to run helpdesk tickets and track their technology assets. Two of the three can be triggered by someone who has no account on the system, over the network, with no help from a logged-in user. Both carry a severity score of 9.8 out of 10.
There is no public report of anyone exploiting them. That is the reassuring half of this story, and on this vendor's record it has a short shelf life.
Two of the three need no login at all
All three flaws are the same class of bug, which the US National Vulnerability Database catalogues as deserialization of untrusted data. Programs store complex objects as a stream of bytes and rebuild them later; the flaw is rebuilding one from data an outsider supplied without checking it first. Ivanti has not published the specifics of how these particular bugs are reached, and its advisory is the only place that detail will appear.
The scores come from Ivanti itself, acting as the assigning authority, and NVD lists all three as still undergoing its own analysis. Ranked by what the published scoring vectors actually say:
- CVE-2026-12650, scored 9.9, the highest of the three. It needs an attacker to hold a low-privileged account, but scores above the others because its impact is recorded as reaching beyond the component that contains the flaw.
- CVE-2026-12744, scored 9.8. Reachable across the network, requires no privileges and no user interaction, and leads to arbitrary code execution on the server.
- CVE-2026-12745, scored 9.8, with an identical scoring vector to the one above.
All three affect Neurons for ITSM before version 2026.2. The entries were published on 8 September 2026. You can read the full record for the first of them in the NVD listing, and Ivanti's own write-up sits in its security advisory for the affected releases.
A vendor CISA has cited 35 times
What makes an unexploited Ivanti bug worth your attention is the company's record. Ivanti products account for 35 entries in CISA's Known Exploited Vulnerabilities catalogue, the US government's list of flaws confirmed to be under attack. The speed matters more than the count. Of the Ivanti flaws added to that list since the start of 2025, IntelFusions records 12, and 7 of them were listed within a week of the CVE first appearing in NVD. Four went up the same day or the next.
That pattern is recent as well as historical. In June we covered a critical Ivanti Sentry flaw that attackers picked up after a public exploit appeared, and in August a set of Ivanti Endpoint Manager bugs that exposed database credentials. Neither looked urgent on the day it was disclosed.
Upgrade to 2026.2
The fix is to move Neurons for ITSM to version 2026.2 or later. Ivanti's advisory is the authority on which specific builds are affected and whether any interim workaround exists, and it is worth reading before you plan the change rather than after. If your deployment is reachable from the internet, handle that part first. Network-reachable plus no authentication is the combination that draws opportunistic scanning as soon as a working exploit circulates.
As of CISA's catalogue dated 11 September 2026, none of the three appears on the exploited list, and EPSS, which estimates the chance a flaw is exploited in the next 30 days, puts all three at roughly 2 percent. Both are snapshots rather than forecasts. It is also worth noting where we are in the calendar: these entries were published on 8 September, so the one-week window that swallowed most of Ivanti's recent KEV additions has not closed yet.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.