Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Ivanti has disclosed a wave of security advisories affecting three flagship enterprise products, Endpoint Manager Mobile, Neurons for ITSM, and Sentry, exposing organizations to risks ranging from privilege escalation to full remote code execution.

The disclosures, published on September 8, 2026, cover ten distinct CVEs, several rated critical, underscoring the breadth of exposure across Ivanti’s mobile device management and IT service management ecosystem.

Ivanti EPMM Vulnerabilities

The first advisory addresses CVE-2026-18851, a high-severity missing authorization flaw in Ivanti Endpoint Manager Mobile (EPMM) carrying a CVSS score of 8.8.

The vulnerability, rooted in CWE-862, allows a remote authenticated attacker to escalate privileges to full administrator access. Versions 12.9.0.1 and earlier, 12.8.0.3 and earlier, and all builds prior to 12.10.0.0 are affected. Ivanti has released fixed versions 12.10.0.0, 12.9.0.2, and 12.8.0.4 to close the gap.

The most severe findings concern Ivanti Neurons for ITSM, where eight separate CVEs were disclosed, three of them carrying a maximum-risk 9.9 critical rating.

Two flaws, CVE-2026-12744 and CVE-2026-12745, involve deserialization of untrusted data (CWE-502) and can be triggered by unauthenticated attackers to execute arbitrary code on the server, each scoring 9.8.

Additional deserialization bugs, CVE-2026-12651, CVE-2026-12650, and CVE-2026-12648, require authentication but still permit remote code execution. Three missing authorization issues, CVE-2026-12645, CVE-2026-12646, and CVE-2026-12647, also enable authenticated attackers to execute code and each rate 9.9 in severity.

Notably, Ivanti disclosed that these ITSM flaws were uncovered through the company’s use of advanced large language models integrated into its product security and engineering workflows, marking a rare instance of AI-assisted vulnerability discovery being credited in a formal advisory.

The cloud and SaaS version of Neurons for ITSM was patched across all landscapes on August 9, 2026, requiring no customer action.

On-premises customers running versions 2025.2 through 2026.1 must apply September 2026 security patches, while version 2026.2 for on-premises deployments is scheduled for release on September 21.

Rounding out the disclosures, CVE-2026-83527 affects Ivanti Sentry deployments managed through EPMM and Neurons for MDM.

This authentication bypass vulnerability, scored 8.1 and classified under CWE-288, lets a remote unauthenticated attacker obtain administrative-level access. Fixed releases R10.8.2, R10.7.3, and R10.6.4 are now available. The flaw was responsibly disclosed by researcher btaol of Aquila Sec Lab.

Product Line CVE Identifier(s) Severity & CVSS Vulnerability Type & Impact Remediation Status
Endpoint Manager Mobile (EPMM) CVE-2026-18851 High (8.8) Missing Authorization (CWE-862) leading to full admin privilege escalation Fixed in versions 12.10.0.0, 12.9.0.2, and 12.8.0.4
Neurons for ITSM CVE-2026-12744, CVE-2026-12745 Critical (9.8) Deserialization of Untrusted Data (CWE-502) enabling unauthenticated RCE Patched in Cloud; Sept 2026 patches for On-Prem 2025.2–2026.1
Neurons for ITSM CVE-2026-12645, CVE-2026-12646, CVE-2026-12647 Critical (9.9) Missing Authorization allowing authenticated remote code execution Patched in Cloud; Sept 2026 patches for On-Prem 2025.2–2026.1
Neurons for ITSM CVE-2026-12651, CVE-2026-12650, CVE-2026-12648 High / Critical Deserialization of Untrusted Data permitting authenticated RCE Patched in Cloud; Sept 2026 patches for On-Prem 2025.2–2026.1
Ivanti Sentry CVE-2026-83527 High (8.1) Authentication Bypass (CWE-288) granting remote unauthenticated admin access Fixed in releases R10.8.2, R10.7.3, and R10.6.4

Ivanti states it has no evidence of active exploitation for any of these vulnerabilities prior to disclosure. Given the historical targeting of Ivanti’s edge and mobile management infrastructure by threat actors, security teams should prioritize patching, particularly for internet-exposed Neurons for ITSM instances, without delay.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacks appeared first on Cyber Security News.