Deserialization Vulnerability in Ivanti Neurons for ITSM by Ivanti
CVE-2026-12744

9.8CRITICAL

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
8 September 2026

What is CVE-2026-12744?

CVE-2026-12744 is a serious deserialization vulnerability found in Ivanti Neurons for ITSM, a product designed to streamline IT service management through automated processes and intelligent insights. This vulnerability allows remote unauthenticated attackers to execute arbitrary code on the impacted server. Such an exploit can undermine the integrity and confidentiality of sensitive data managed by the application, as well as disrupt essential IT service operations. Organizations that rely on Ivanti’s platform for their IT service management may face significant risks if this vulnerability is not addressed, as it exposes them to potential system takeover and malicious activities.

Potential Impact of CVE-2026-12744

  1. Arbitrary Code Execution: The most critical impact of CVE-2026-12744 is the ability for attackers to execute arbitrary code on the server. This can lead to unauthorized access and control over IT infrastructure, significantly increasing the risk of data breaches and other malicious activities.

  2. Disruption of IT Services: Exploitation of this vulnerability could compromise the functionality of IT service management systems, leading to interruptions in service delivery and potentially causing operational downtime. This could affect an organization’s ability to respond to IT issues promptly.

  3. Data Integrity and Confidentiality Risks: By gaining control over the Ivanti Neurons for ITSM server, an attacker could manipulate or exfiltrate sensitive organizational data. The loss of data integrity and breaches of confidential information could have severe repercussions, including regulatory penalties and damage to the organization's reputation.

Affected Version(s)

Neurons for ITSM 2026.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.