Breaking
SecurityDeveloping Story

Ivanti's Patch Cascade: Critical RCE Flaws Resolved

Ivanti addresses critical and high-severity vulnerabilities across Neurons for ITSM, Sentry, and EPMM, urging immediate updates.

··1 hour ago·4 min read
a close up of a network with wires connected to it
Photo by Albert Stoynov on Unsplash

Ivanti is rolling out a wave of security updates across three enterprise product lines this week, closing off a cluster of critical and high-severity vulnerabilities that, if left unpatched, could hand attackers a direct route to remote code execution and administrative control. The company’s Tuesday advisory covers flaws in Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM), with the bulk of the most serious issues concentrated in its IT service management platform.

Eight Flaws, Six Critical in ITSM

According to Ivanti, the Neurons for ITSM update addresses the largest number of security defects in this release—eight bugs in total. Six of those are rated critical severity, and Ivanti warns that they could lead to remote code execution. The affected product is widely used for IT service management, making these flaws particularly consequential for organizations that rely on it for day-to-day operations.

The critical issues include CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646, each carrying a CVSS score of 9.9 out of 10 and described as missing authorization issues. Three more critical flaws—CVE-2026-12650 (CVSS 9.9), CVE-2026-12744 (CVSS 9.8), and CVE-2026-12745 (CVSS 9.8)—are characterized as deserialization of untrusted data weaknesses. Ivanti also fixed two high-severity deserialization issues, tracked as CVE-2026-12651 and CVE-2026-12648, which similarly could lead to remote code execution.

Authentication Required, But Not Always

Ivanti’s advisory notes that only two of the eight Neurons for ITSM vulnerabilities—CVE-2026-12744 and CVE-2026-12745—can be exploited without authentication. That distinction matters for defenders prioritizing which flaws to patch first, since unauthenticated exploitation typically removes a significant barrier for attackers. The remaining flaws, while still serious, require some level of access or authentication to trigger.

All eight vulnerabilities were addressed in the September 2026 security updates for Neurons for ITSM versions 2025.2, 2025.3, 2025.4, and 2026.1. Ivanti also plans to include the fixes in version 2026.2 of the product, which is scheduled for September 21. The company is explicitly urging customers running on-premises deployments to take action.

“Customers using the on-premises version of Ivanti Neurons for ITSM should update their solution to one of the resolved versions to address the vulnerabilities,”

— Ivanti, in its security advisory

Sentry and EPMM Also Patched

Ivanti’s Tuesday releases extend beyond ITSM. The company rolled out Sentry versions R10.8.2, R10.7.3, and R10.6.4 to fix CVE-2026-83527, a high-severity authentication bypass that could allow remote, unauthenticated attackers to gain administrative privileges. Sentry is Ivanti’s secure gateway product, often deployed at the network perimeter, which makes an unauthenticated admin-level bypass a particularly worrying prospect.

On the same day, EPMM versions 12.10.0.0, 12.9.0.2, and 12.8.0.4 were released to resolve CVE-2026-18851, another high-severity authentication bypass. Unlike the Sentry flaw, this one requires authentication for successful exploitation, according to Ivanti. EPMM is used for enterprise mobile device management, so the bug could impact organizations managing fleets of smartphones and tablets.

No Exploitation Observed Yet

For now, Ivanti says it is not aware of any of these vulnerabilities having been exploited in the wild. The company also notes that no other Ivanti products are affected by the issues disclosed in this batch. That provides some breathing room for security teams, though the lack of active exploitation does not diminish the urgency of patching—especially given the severity ratings and the potential for attackers to reverse-engineer fixes once they are public.

The disclosure fits into a broader pattern of vendors shipping security updates on the same day. Citrix also announced fixes on Tuesday for two medium-severity flaws in its Workspace app for Windows: an out-of-bounds read that requires local access, and an out-of-bounds write that requires physical access to an affected system. These are less severe than Ivanti’s criticals, but they add to the workload for defenders already juggling multiple vendor advisories.

The Patch Burden Grows

Ivanti’s update lands in a period of intense vendor activity, with several other significant disclosures surfacing around the same time. Microsoft recently patched a record 974 vulnerabilities, including two exploited zero-days. Adobe addressed over 170 vulnerabilities, with a Commerce zero-day among them. N-able fixed a critical zero-day in N-central, and a 12-year-old PostgreSQL vulnerability was patched that could enable database and server takeover. For security teams, the volume of critical fixes is relentless, and tracking which ones apply to their environment is a constant challenge.

This steady stream of updates across major vendors puts pressure on IT departments to maintain a disciplined patch management process. The Ivanti flaws, particularly those in Neurons for ITSM, affect a product that is itself often used to manage IT operations—meaning the patching process could be more complex if the platform is central to an organization's workflow.

What This Means for Defenders

For organizations using Ivanti products, the immediate takeaway is clear: prioritize patching the on-premises versions of Neurons for ITSM, Sentry, and EPMM to the latest available releases. The unauthenticated flaws in ITSM and Sentry deserve the highest attention, as they represent the lowest barrier to exploitation. Given the severity scores and the potential for remote code execution or administrative takeover, delaying these updates could expose networks to significant risk.

The absence of known exploitation is a positive sign, but it is not a guarantee of safety. Attackers often reverse-engineer patches to develop exploits, and the gap between disclosure and exploitation in enterprise environments can be short. Ivanti’s advisory, along with the fixes from Citrix and others, underscores the necessity of an agile patching strategy—one that can respond quickly when vendors release updates.

#ivanti#patch tuesday#remote code execution#authentication bypass#critical vulnerabilities

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories