Deserialization Vulnerability in Ivanti Neurons for ITSM by Ivanti
CVE-2026-12744
9.8CRITICAL
What is CVE-2026-12744?
A vulnerability exists in Ivanti Neurons for ITSM that allows remote unauthenticated attackers to exploit deserialization of untrusted data, potentially leading to arbitrary code execution on the server. This issue affects versions prior to 2026.2, presenting a serious risk to ITSM environments if not patched.
Affected Version(s)
Neurons for ITSM 2026.2