Deserialization Vulnerability in Ivanti Neurons for ITSM by Ivanti
CVE-2026-12744
What is CVE-2026-12744?
CVE-2026-12744 is a serious deserialization vulnerability found in Ivanti Neurons for ITSM, a product designed to streamline IT service management through automated processes and intelligent insights. This vulnerability allows remote unauthenticated attackers to execute arbitrary code on the impacted server. Such an exploit can undermine the integrity and confidentiality of sensitive data managed by the application, as well as disrupt essential IT service operations. Organizations that rely on Ivanti’s platform for their IT service management may face significant risks if this vulnerability is not addressed, as it exposes them to potential system takeover and malicious activities.
Potential Impact of CVE-2026-12744
-
Arbitrary Code Execution: The most critical impact of CVE-2026-12744 is the ability for attackers to execute arbitrary code on the server. This can lead to unauthorized access and control over IT infrastructure, significantly increasing the risk of data breaches and other malicious activities.
-
Disruption of IT Services: Exploitation of this vulnerability could compromise the functionality of IT service management systems, leading to interruptions in service delivery and potentially causing operational downtime. This could affect an organization’s ability to respond to IT issues promptly.
-
Data Integrity and Confidentiality Risks: By gaining control over the Ivanti Neurons for ITSM server, an attacker could manipulate or exfiltrate sensitive organizational data. The loss of data integrity and breaches of confidential information could have severe repercussions, including regulatory penalties and damage to the organization's reputation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Neurons for ITSM 2026.2