Ivanti released fixes for ten vulnerabilities across Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry. The most urgent Neurons for ITSM issues are unauthenticated deserialization flaws CVE-2026-12744 and CVE-2026-12745, which can enable remote code execution on versions before 2026.2; additional missing-authorization and deserialization flaws, including CVE-2026-12646, CVE-2026-12647, CVE-2026-12648, CVE-2026-12650, and CVE-2026-12651, allow low-privileged authenticated users to execute code. Ivanti patched its cloud/SaaS ITSM environments and directed on-premises customers on versions 2025.2 through 2026.1 to apply the September security updates.
EPMM vulnerability CVE-2026-18851 is a CVSS 8.8 missing-authorization flaw that lets a remote authenticated attacker elevate privileges to administrator; affected customers should upgrade to 12.10.0.0, 12.9.0.2, or 12.8.0.4. Ivanti Sentry vulnerability CVE-2026-83527 permits unauthenticated attackers to gain administrative-level access in releases before R10.8.2, R10.7.3, and R10.6.4. Ivanti and CISA reported no known exploitation at disclosure, but organizations should prioritize remediation of internet-exposed Neurons for ITSM deployments and review all applicable vendor advisories.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-897 covering affected Ivanti Endpoint Manager Mobile, Neurons for ITSM, and Sentry versions. It urged administrators to review Ivanti advisories and apply available updates.
CISA SSVC records dated September 8 assessed the listed EPMM, Neurons for ITSM, and Sentry CVEs as having no known exploitation and total technical impact. The records marked CVE-2026-12744 and CVE-2026-12745 as automatable, while the other referenced vulnerabilities were assessed as not automatable.
Ivanti stated it had no evidence that any of the ten disclosed vulnerabilities had been actively exploited before disclosure. For CVE-2026-18851, it also said there was no known public exploitation or associated public indicators of compromise.
Ivanti released EPMM fixes 12.10.0.0, 12.9.0.2, and 12.8.0.4 for CVE-2026-18851, and Sentry fixes R10.8.2, R10.7.3, and R10.6.4 for CVE-2026-83527. It directed Neurons for ITSM on-premises customers running releases 2025.2 through 2026.1 to apply September 2026 security patches.
Ivanti disclosed ten CVEs affecting Endpoint Manager Mobile, Neurons for ITSM, and Sentry. The issues included EPMM privilege escalation (CVE-2026-18851), eight Neurons for ITSM flaws including unauthenticated RCE vulnerabilities CVE-2026-12744 and CVE-2026-12745, and Sentry authentication bypass CVE-2026-83527.
Ivanti patched all Neurons for ITSM cloud and SaaS landscapes, with no customer action required.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
19 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourceacn.gov.it
Open sourcesecurityweek.com
Open sourcemalware.news
Open sourcecvefeed.io
Open sourcehub.ivanti.com
Open sourcehub.ivanti.com
Open sourcehub.ivanti.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.