Ivanti patches 10 CVEs: two unauthenticated RCEs in ITSM
Ivanti's September 2026 update fixes 10 CVEs across Neurons for ITSM, EPMM and Sentry — six critical, two exploitable with no login at all. Patch order matters.
Ivanti disclosed 10 CVEs on September 8, spread across Neurons for ITSM, Endpoint Manager Mobile and Sentry. Six are critical. Two of them need no authentication whatsoever. If your MSP runs Ivanti — or if your ticketing system is Neurons for ITSM — the patch order here is not obvious, and getting it wrong leaves the worst hole open longest.
What actually happened
Eight of the ten flaws sit in Neurons for ITSM, the service-desk product. Per SecurityWeek's breakdown, four carry a CVSS of 9.9 — CVE-2026-12645, CVE-2026-12646 and CVE-2026-12647 are missing-authorization bugs, and CVE-2026-12650 is a deserialization flaw. All four still require a valid session.
The two that do not are CVE-2026-12744 and CVE-2026-12745, both CVSS 9.8 deserialization-of-untrusted-data defects, both reachable by an unauthenticated attacker, both ending in remote code execution. Those are your first two, regardless of what your vulnerability scanner sorted to the top.
Sentry gets CVE-2026-83527, an authentication bypass in deployments managed through EPMM or Neurons for MDM, fixed in R10.8.2, R10.7.3 and R10.6.4. EPMM gets CVE-2026-18851, which hands an attacker administrator-level access, fixed in 12.10.0.0, 12.9.0.2 and 12.8.0.4.
Cloud and SaaS Neurons for ITSM was already patched across all landscapes back in August — nothing to do there. On-premises installs running 2025.2 through 2026.1 need the September patch now. The 2026.2 on-prem release does not ship until September 21, so anyone waiting on that version is exposed for twelve more days. Ivanti says it has no evidence of exploitation in the wild.
Why this patch cycle matters for your business
Notice what the affected products have in common: they are the tools that manage everything else. A service desk holds ticket history, asset inventory and often credentials pasted into resolution notes. An MDM console can push a payload to every phone in the company. These are not leaf systems. Compromise here is lateral movement with a badge on.
That reframes the "no evidence of exploitation" line. It is accurate and it is temporary. Deserialization bugs in enterprise software get reverse-engineered from the patch diff, and the two unauthenticated ones are the ones researchers will start with. Assume the window is days.
Three things to do this week. First, ask whoever runs your Ivanti stack for the exact running version string in writing — not "we're patched," the number. Second, confirm whether your Neurons for ITSM is cloud or on-prem, because the answer decides whether you have work at all. Third, if the answer is "we're on 2026.1 and waiting for 2026.2," push the September patch now and take the upgrade later. A scheduled version bump is not a mitigation.
And if you inherited these tools from a managed provider who has not called you about this yet, that silence is its own finding.
Key takeaways
- Ivanti disclosed 10 CVEs on September 8 across Neurons for ITSM, EPMM and Sentry; six are critical
- CVE-2026-12744 and CVE-2026-12745 (CVSS 9.8) are unauthenticated RCE — patch these first
- Four CVSS 9.9 ITSM flaws require authentication, so they rank second despite the higher score
- Cloud/SaaS ITSM was patched in August; on-prem 2025.2 through 2026.1 needs the September update now
- On-prem 2026.2 does not ship until September 21 — do not treat the upgrade as the fix
- Ivanti reports no known exploitation, but patch-diff analysis makes that a days-long window
The tools that manage your other tools deserve their own patch SLA. We build the inventory and alerting that tells you which version is actually running on which box, so a vendor advisory turns into a checklist instead of a phone tree. See how we handle infrastructure and patching, or send us the stack you inherited and cannot fully account for.
Sources: Ivanti September 2026 Security Update, SecurityWeek.
- #ivanti
- #cve
- #patching
- #rce
- #it-service-management
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Attackers built and ran an agent campaign in six hours
Google's threat team watched an intruder plan, build and execute mass credential harvesting in under six hours using an agent framework. Your response window just shrank.
Read itcPanel CVE-2026-67401: a mail account becomes root
A SQL injection in cPanel's Email Track lets an authenticated account with mail privileges write files and execute code as root. Patched builds are out — check yours.
Read it