Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2724+ Articles
166+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. Security
  3. CVE-2026-12645 & CVE-2026-12646: Ivanti Neurons for ITSM Missing-Authorization RCE Flaws
CVE-2026-12645 & CVE-2026-12646: Ivanti Neurons for ITSM Missing-Authorization RCE Flaws

Critical Security Alert

This vulnerability is actively being exploited. Immediate action is recommended.

SECURITYCRITICALCVE-2026-12645

CVE-2026-12645 & CVE-2026-12646: Ivanti Neurons for ITSM Missing-Authorization RCE Flaws

Two CVSS 9.9 missing-authorization bugs in Ivanti Neurons for ITSM let any authenticated user run code on the server. On-prem admins must patch.

Dylan H.

Security Team

September 9, 2026
3 min read

Affected Products

  • Ivanti Neurons for ITSM (on-premises, versions 2025.2 – 2026.1)

Overview

Ivanti disclosed a batch of security fixes for Neurons for ITSM on September 8, 2026, including three related missing-authorization vulnerabilities — CVE-2026-12645, CVE-2026-12646, and CVE-2026-12647 — that each carry a CVSS v3.1 score of 9.9 (Critical). All three stem from the same root cause: Ivanti Neurons for ITSM before version 2026.2 fails to properly check authorization on certain server-side operations, allowing a remote authenticated attacker to execute arbitrary code on the server.

Because exploitation only requires low privileges and no user interaction, any account on a vulnerable ITSM instance — including a low-tier helpdesk or end-user account — is a potential launch point for full server compromise.

AttributeValue
CVE IDsCVE-2026-12645, CVE-2026-12646 (+ CVE-2026-12647)
CWECWE-862 — Missing Authorization
CVSS v3.19.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
ImpactRemote code execution as an authenticated user
AffectedNeurons for ITSM before 2026.2 (on-premises)
Fixed in2025.2, 2025.3, 2025.4, and 2026.1 September 2026 security updates; baked into 2026.2

What's Actually Broken

Both CVEs share Ivanti's own advisory language almost verbatim: a missing authorization check in Neurons for ITSM lets a remote, authenticated user execute arbitrary code on the server. The scope flag in the CVSS vector (S:C) means the impact isn't confined to the ITSM application itself — a successful exploit can affect resources beyond the vulnerable component.

This disclosure was part of a larger round of Ivanti Neurons for ITSM fixes — eight CVEs in total — that also included:

  • Two unauthenticated deserialization flaws (CVE-2026-12744, CVE-2026-12745, both CVSS 9.8) that don't even require a valid login
  • Three additional authenticated deserialization RCE bugs (CVE-2026-12648, CVE-2026-12650, CVE-2026-12651)

The same September update cycle also shipped fixes for Ivanti EPMM (CVE-2026-18851) and Ivanti Sentry (CVE-2026-83527).

Notably, Ivanti credits its own LLM-assisted internal security review process for surfacing this batch of flaws — an unusually explicit acknowledgment of AI-assisted vulnerability discovery in a vendor advisory.

Who's Affected

  • Ivanti Neurons for ITSM Cloud/SaaS: Already patched across all landscapes as of August 9, 2026. No customer action required.
  • Ivanti Neurons for ITSM on-premises, versions 2025.2, 2025.3, 2025.4, and 2026.1: Vulnerable until the September 2026 security patch is applied.
  • Version 2026.2, scheduled for release September 21, 2026, ships with the fixes included.

There is currently no public evidence of active exploitation, but the low bar for exploitation — any authenticated account, no interaction needed — makes this a priority patch for any organization running ITSM on-premises, particularly instances with self-service portals or broad internal user access.

Recommendations

  1. On-premises customers: Apply the September 2026 security patch for your Neurons for ITSM version (2025.2 – 2026.1) immediately; do not wait for the 2026.2 release.
  2. SaaS/Cloud customers: Confirm your tenant received the August 9, 2026 patch — no further action should be needed, but verify with Ivanti support if uncertain.
  3. Audit authenticated-user access: Since exploitation only requires low-privilege authentication, review who holds ITSM accounts and tighten onboarding/offboarding hygiene in the interim.
  4. Monitor for anomalous server-side activity on ITSM hosts — unexpected process spawns or file writes triggered by helpdesk/end-user sessions — until patched.

References

  • Ivanti Security Advisory
  • SecurityWeek — Ivanti Patches Critical Flaws Across Enterprise Security Products
  • NVD — CVE-2026-12645
  • NVD — CVE-2026-12646

Related Reading

  • CVE-2026-1340: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
#Ivanti#Neurons for ITSM#CVE-2026-12645#CVE-2026-12646#Missing Authorization#RCE

Related Articles

CVE-2026-26026: GLPI Template Injection Enables

GLPI versions 11.0.0 through 11.0.5 contain a server-side template injection vulnerability in the administrator interface that allows authenticated admins...

7 min read

CVE-2026-53469: migration-planner Missing Authorization on Bulk Delete

A critical missing authorization vulnerability (CVSS 9.1) in Red Hat's migration-planner allows any authenticated user to send a DELETE request to...

4 min read

Ivanti Warns of New EPMM Flaw Exploited in Zero-Day Attacks

Ivanti has issued an urgent advisory warning customers to patch a high-severity remote code execution vulnerability in Endpoint Manager Mobile (EPMM) that...

4 min read
Back to all Security Alerts