Critical severity9.9NVD Advisory· Published Sep 8, 2026· Updated Sep 8, 2026
CVE-2026-12650
CVE-2026-12650
Description
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Affected products
1- Range: <2026.2
Patches
Vulnerability mechanics
References
1News mentions
1- Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE AttacksCyber Security News · Sep 8, 2026