Critical Ivanti EPMM, Neurons, Sentry Flaws Allow RCE, Privilege Escalation
Key Takeaways Ivanti has released multiple security advisories for its Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry products. Ten distinct CVEs were disclosed on September 8, 2026,...
Key Takeaways
- Ivanti has released multiple security advisories for its Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry products.
- Ten distinct CVEs were disclosed on September 8, 2026, including several critical vulnerabilities with CVSS scores up to 9.9.
- The flaws enable various attacks, from privilege escalation to unauthenticated remote code execution.
- Patches are available for all affected products, with some cloud versions already updated automatically.
- Notably, some Ivanti Neurons for ITSM vulnerabilities were discovered with the aid of large language models.
Ivanti Products Face Critical Security Flaws, Including RCE and Privilege Escalation Risks
Ivanti has issued a series of urgent security advisories impacting three of its prominent enterprise solutions: Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry. These disclosures, made public on September 8, 2026, detail ten separate Common Vulnerabilities and Exposures (CVEs) that could leave organizations vulnerable to a spectrum of attacks, from elevated privileges to full remote code execution (RCE).
Table Of Content
The vulnerabilities span Ivanti’s mobile device management and IT service management offerings, with several rated as critical severity, highlighting a broad risk surface for enterprise users.
Ivanti EPMM Vulnerabilities
Among the identified issues, the first advisory addresses CVE-2026-18851, a high-severity flaw within Ivanti Endpoint Manager Mobile (EPMM). This vulnerability, categorized as a missing authorization issue (CWE-862), carries a CVSS score of 8.8. It allows an authenticated remote attacker to escalate their privileges to full administrative access. Affected versions include 12.9.0.1 and earlier, 12.8.0.3 and earlier, and all builds preceding 12.10.0.0. Ivanti has released patches in versions 12.10.0.0, 12.9.0.2, and 12.8.0.4 to mitigate this risk.
Ivanti Neurons for ITSM Critical Vulnerabilities
The most significant findings concern Ivanti Neurons for ITSM, where eight distinct CVEs were unveiled. Three of these have been assigned a critical CVSS score of 9.9, the maximum risk rating.
Two critical flaws, CVE-2026-12744 and CVE-2026-12745, involve the deserialization of untrusted data (CWE-502). These can be exploited by unauthenticated attackers to achieve arbitrary code execution on the server, each earning a CVSS score of 9.8.
Further deserialization vulnerabilities, identified as CVE-2026-12651, CVE-2026-12650, and CVE-2026-12648, also enable remote code execution, though they require prior authentication. Additionally, three missing authorization issues (CVE-2026-12645, CVE-2026-12646, and CVE-2026-12647) allow authenticated attackers to execute code, each rated with a critical severity of 9.9.
In a notable disclosure, Ivanti credited the discovery of these ITSM vulnerabilities to its internal use of advanced large language models integrated into its product security and engineering workflows. This marks one of the rare instances where AI-assisted vulnerability discovery has been formally acknowledged in a security advisory.
For Ivanti Neurons for ITSM, the cloud and SaaS versions received automatic patches across all environments on August 9, 2026, requiring no action from customers. On-premises customers utilizing versions 2025.2 through 2026.1 must apply the September 2026 security patches. Version 2026.2 for on-premises deployments is slated for release on September 21.
Ivanti Sentry Authentication Bypass
Completing the series of advisories, CVE-2026-83527 affects Ivanti Sentry instances managed via EPMM and Neurons for MDM. This high-severity authentication bypass vulnerability, with a CVSS score of 8.1 and classified as CWE-288, permits a remote, unauthenticated attacker to gain administrative-level access. Fixed releases R10.8.2, R10.7.3, and R10.6.4 are now available. The flaw was responsibly reported by security researcher btaol of Aquila Sec Lab.
Ivanti has stated that, as of the disclosure date, there is no evidence of active exploitation for any of these vulnerabilities. However, given the historical targeting of Ivanti’s network edge and mobile management infrastructure by malicious actors, security teams are strongly advised to prioritize patching, particularly for internet-facing Neurons for ITSM instances, without delay.
What You Should Do
- Patch Ivanti EPMM: Update to versions 12.10.0.0, 12.9.0.2, or 12.8.0.4 immediately.
- Update Ivanti Neurons for ITSM (On-Premises): Apply the September 2026 security patches if running versions 2025.2 through 2026.1. Cloud/SaaS users are already patched.
- Patch Ivanti Sentry: Upgrade to releases R10.8.2, R10.7.3, or R10.6.4.
- Prioritize Internet-Exposed Systems: Focus patching efforts on any Ivanti Neurons for ITSM instances accessible from the internet due to the critical RCE risks.
- Review Access Controls: Ensure robust authentication and authorization mechanisms are in place across all Ivanti deployments.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.