Vulnerability
Published 2026-09-08
Verified 2026-09-19

Ivanti Neurons for ITSM critical RCE set; Sentry/EPMM auth bypass (Sep 2026)

Ivanti's 8–9 September 2026 security update discloses flaws in Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM). SecurityWeek citing Ivanti: Neurons for ITSM has eight bugs including six critical — missing-authorization CVE-2026-12647/12645/12646 (CVSS 9.9) and deserialization CVE-2026-12650 (9.9), CVE-2026-12744/12745 (9.8); only CVE-2026-12744 and CVE-2026-12745 are unauthenticated per that coverage. Fixed in Neurons for ITSM 2025.2/2025.3/2025.4/2026.1 September builds (2026.2 due 21 Sep). Sentry R10.8.2 / R10.7.3 / R10.6.4 patch high auth bypass CVE-2026-83527 (unauth admin). EPMM 12.10.0.0 / 12.9.0.2 / 12.8.0.4 patch high auth bypass CVE-2026-18851 (authenticated). Ivanti blog: no evidence of exploitation in the wild; other Ivanti products not affected. Primary vendor posts: Ivanti September 2026 Security Update blog and Neurons for ITSM hub advisory.

Product
Ivanti Neurons for ITSM; Ivanti Sentry; Ivanti EPMM
Versions
Neurons for ITSM: update 2025.2/2025.3/2025.4/2026.1 Sep builds; Sentry R10.8.2/R10.7.3/R10.6.4; EPMM 12.10.0.0/12.9.0.2/12.8.0.4
CVSS
Neurons criticals up to 9.9 (SecurityWeek citing Ivanti); Sentry/EPMM high auth bypass
Exploited in Australia?
unknown
Patch to
Apply Ivanti September 2026 builds for Neurons for ITSM, Sentry, and EPMM per vendor advisories

Primary: Ivanti September 2026 Security Update blog (8 Sep 2026) · Vendor: Ivanti hub — Neurons for ITSM Multiple CVEs · CVE: CVE-2026-12647, CVE-2026-12650, CVE-2026-12744, CVE-2026-12745, CVE-2026-83527, CVE-2026-18851 · SecurityWeek (9 Sep 2026)

vulnerabilities identity cloud network