Ivanti has recently rolled out essential security updates aimed at rectifying critical and high-severity vulnerabilities within its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) platforms. These updates, announced on Tuesday, are crucial for maintaining the security integrity of these widely-used enterprise security products.
Significant Vulnerabilities in Neurons for ITSM
The Neurons for ITSM platform has undergone significant patching, addressing eight security flaws. Of these, six are deemed critical, with potential to enable remote code execution. Notable vulnerabilities include CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646, each with a CVSS score of 9.9, indicating missing authorization issues. Additional critical flaws are CVE-2026-12650, CVE-2026-12744, and CVE-2026-12745, all with high CVSS scores due to deserialization of untrusted data.
The remaining two vulnerabilities, CVE-2026-12651 and CVE-2026-12648, while classified as high-severity, also involve the deserialization of untrusted data, posing risks of remote code execution. Notably, CVE-2026-12744 and CVE-2026-12745 can be exploited without authentication, increasing their threat potential.
Updates for Sentry and EPMM Products
In addition to Neurons for ITSM, Ivanti has provided updates for its Sentry and EPMM products. Sentry versions R10.8.2, R10.7.3, and R10.6.4 address CVE-2026-83527, a high-severity vulnerability that allows remote attackers to bypass authentication and gain administrative access without credentials.
EPMM has also been updated to versions 12.10.0.0, 12.9.0.2, and 12.8.0.4, resolving CVE-2026-18851. This high-severity flaw requires authentication for exploitation, differing from the Sentry vulnerability.
According to Ivanti, there have been no reports of these vulnerabilities being exploited in real-world scenarios, and no other Ivanti products are affected at this time.
Importance of Immediate Updates
Ivanti advises all users of the on-premises version of Neurons for ITSM to upgrade to a patched version to mitigate these vulnerabilities. The addressed flaws are included in the September 2026 security updates for versions 2025.2, 2025.3, 2025.4, and 2026.1, with further updates planned for version 2026.2, set for release on September 21.
In related news, Citrix has announced patches for medium-severity vulnerabilities in its Workspace app for Windows, highlighting the ongoing need for vigilance in software security. Other notable updates include Microsoft’s record 974 vulnerability patches and Adobe’s extensive vulnerability fixes.
As cybersecurity threats continue to evolve, timely implementation of security patches remains imperative to safeguarding enterprise systems against potential exploits.
