Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Network Security

Ivanti Patches Critical Flaws Across Enterprise Security Products

Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws.

Ivanti vulnerability

Ivanti on Tuesday announced security updates that address vulnerabilities rated critical and high severity in its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) products.

Neurons for ITSM received fixes for the largest number of security defects. Of the eight bugs, six are critical-severity issues that could lead to remote code execution, Ivanti warns.

These include CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646 (CVSS score of 9.9/10), described as missing authorization issues; and CVE-2026-12650 (CVSS score of 9.9/10), CVE-2026-12744, and CVE-2026-12745 (CVSS score of 9.8/10), described as deserialization of untrusted data weaknesses.

The remaining two bugs, tracked as CVE-2026-12651 and CVE-2026-12648, are high-severity deserialization of untrusted data defects also leading to remote code execution.

According to Ivanti’s advisory, only CVE-2026-12744 and CVE-2026-12745 can be exploited without authentication.

All vulnerabilities were addressed with the September 2026 security updates rolled out for Neurons for ITSM versions 2025.2, 2025.3, 2025.4, and 2026.1. The fixes will also be included in version 2026.2 of the product, scheduled for September 21.

Advertisement. Scroll to continue reading.

“Customers using the on-premises version of Ivanti Neurons for ITSM should update their solution to one of the resolved versions to address the vulnerabilities,” Ivanti notes.

On Tuesday, Ivanti released Sentry versions R10.8.2, R10.7.3, and R10.6.4 with patches for CVE-2026-83527, a high-severity authentication bypass that could allow remote, unauthenticated attackers to gain administrative privileges.

EPMM versions 12.10.0.0, 12.9.0.2, and 12.8.0.4 were released on Tuesday to resolve CVE-2026-18851, another high-severity authentication bypass. Unlike the Sentry bug, this one requires authentication for successful exploitation.

Ivanti says it is not aware of any of these vulnerabilities being exploited in the wild. No other Ivanti products are affected, the company notes.

Also on Tuesday, Citrix announced fixes for two medium-severity flaws in its Workspace app for Windows: an out-of-bounds read that requires local access, and an out-of-bounds write that requires physical access to an affected system.

Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Related: N-able Patches Critical Zero-Day in N-central

Related: 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Frank Verdecanna has been appointed Chief Financial Officer at Armadin.

Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.

Skyhigh Security has named Anthony Palladino as Chief Operating Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.