Ivanti Patches Ten Vulnerabilities Across EPMM, Neurons for ITSM, and Sentry Products
Ivanti has released security advisories for ten vulnerabilities across its EPMM, Neurons for ITSM, and Sentry products, including critical flaws enabling unauthenticated remote code execution.

Ivanti has issued urgent security advisories for ten vulnerabilities affecting its Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry products. These flaws range in severity, with several critical vulnerabilities allowing for privilege escalation and remote code execution (RCE), posing significant risks to organizations utilizing these enterprise management solutions.
The most critical findings are within Ivanti Neurons for ITSM, where eight distinct CVEs have been disclosed. Three of these, CVE-2026-12744, CVE-2026-12745, and CVE-2026-12645 through CVE-2026-12647, carry the highest CVSS score of 9.9. The unauthenticated RCE flaws, CVE-2026-12744 and CVE-2026-12745, stem from deserialization of untrusted data (CWE-502) and can be exploited by attackers without prior authentication. Other ITSM vulnerabilities, including CVE-2026-12651, CVE-2026-12650, CVE-2026-12648, and the aforementioned missing authorization flaws, allow authenticated attackers to achieve RCE.
Notably, Ivanti highlighted that these Neurons for ITSM vulnerabilities were discovered through the company's integration of advanced large language models (LLMs) into its product security workflows. This marks a significant instance where AI-assisted vulnerability research has directly contributed to the identification of critical security flaws. The cloud and SaaS versions of Neurons for ITSM have already been patched, while on-premises customers are urged to apply the September 2026 security patches for affected versions.
Beyond ITSM, Ivanti EPMM is affected by CVE-2026-18851, a high-severity (CVSS 8.8) missing authorization vulnerability (CWE-862). This flaw allows an authenticated remote attacker to escalate their privileges to full administrator access. Ivanti has released updated versions of EPMM to address this issue, with specific version numbers provided for affected deployments.
Ivanti Sentry also faces a critical vulnerability, CVE-2026-83527, an authentication bypass flaw (CWE-288) with a CVSS score of 8.1. This vulnerability, discovered by researcher btaol of Aquila Sec Lab, enables unauthenticated remote attackers to gain administrative-level access to Sentry deployments managed via EPMM or Neurons for MDM. Patched releases for Sentry are now available.
While Ivanti has stated there is no evidence of active exploitation for these vulnerabilities prior to their disclosure, the historical targeting of Ivanti's infrastructure by threat actors necessitates prompt action. Security teams are strongly advised to prioritize patching, especially for internet-facing Ivanti Neurons for ITSM instances, to mitigate the risk of potential exploitation.
The disclosure underscores the ongoing challenges in securing complex enterprise software ecosystems and highlights the increasing role of AI in both vulnerability discovery and the potential for exploitation. Organizations must remain vigilant in applying security updates and monitoring their environments for any signs of compromise.