Alanna
River

Ivanti Vulnerabilities: Critical ITSM RCE and Admin Access Flaws

Alanna River

Sep 15, 2026

6 min read

Ivanti vulnerabilities

TL;DR

Ivanti disclosed ten vulnerabilities affecting Neurons for ITSM, Sentry, and Endpoint Manager Mobile on September 8, 2026. The Ivanti vulnerabilities include two unauthenticated remote code execution flaws in Neurons for ITSM, an unauthenticated authentication bypass in Sentry, and an authenticated privilege-escalation flaw in EPMM.

Successful exploitation could let an attacker execute code on an ITSM server or obtain administrative access to a security management product. However, Ivanti reported no evidence of exploitation before disclosure, and no threat actor or attack campaign has been identified.

Organizations should identify affected deployments, install the vendor’s updates, restrict management interfaces, and review administrator activity. Hexnode UEM can complement this work by enforcing security baselines and monitoring compliance across enrolled endpoints, but it does not replace the Ivanti patches.

Introduction

Security tools need the same patching discipline as the systems they protect.

On September 8, 2026, Ivanti released updates for ten vulnerabilities affecting Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM). The Ivanti vulnerabilities could enable remote code execution, authentication bypass, or administrative privilege escalation, depending on the affected product.

Two Neurons for ITSM flaws and the Sentry vulnerability do not require authentication. That makes exposed or broadly accessible management interfaces particularly important to identify and patch. Ivanti had not reported evidence of exploitation before disclosure.

Who is Ivanti?

Ivanti is an enterprise software vendor whose products support IT service management, endpoint management, mobile access, and related security operations. The products affected by the September 2026 advisories occupy privileged positions within enterprise environments.

Neurons for ITSM manages service requests and IT workflows. EPMM provides mobile device and application management, while Sentry acts as a gateway between managed mobile devices and protected enterprise resources.

These roles make access control and code execution flaws operationally significant. A successful attacker could potentially gain control over the affected product or interfere with administrative functions. However, these advisories describe software vulnerabilities rather than a confirmed attack campaign, and no threat actor has been attributed to them.

What happened?

Ivanti disclosed separate security advisories for Neurons for ITSM, Sentry, and EPMM. The flaws have different authentication requirements and should not be treated as a single attack chain.

Incident detail Verified information
Disclosure date September 8, 2026
Threat actor No threat actor or group has been identified
Affected organizations Organizations operating vulnerable Neurons for ITSM, Sentry, or EPMM deployments
Initial access Network access to the affected product is required; authentication requirements vary by vulnerability
Social engineering None reported or required by the disclosed vulnerability conditions
Credential or MFA impact No credential theft or MFA bypass was reported
Persistence No persistence method was reported
Data or access at risk Potential server-side code execution or administrative access, depending on the product
Confirmed exploitation Ivanti reported no evidence that the flaws had been exploited before disclosure
Confirmed impact The advisories confirm vulnerable software and potential impact, not a successful breach or data theft

Eight Neurons for ITSM vulnerabilities

Neurons for ITSM received fixes for eight vulnerabilities: six critical flaws and two high-severity flaws. All eight could allow a remote attacker to execute arbitrary code on the affected server.

CVE-2026-12744 and CVE-2026-12745 are critical deserialization-of-untrusted-data vulnerabilities with CVSS scores of 9.8. A remote attacker can exploit these flaws without authentication.

CVE-2026-12645, CVE-2026-12646, and CVE-2026-12647 are missing-authorization vulnerabilities. CVE-2026-12650 is another deserialization flaw. These four critical vulnerabilities require authentication and carry CVSS scores of 9.9.

CVE-2026-12648 and CVE-2026-12651 are high-severity deserialization vulnerabilities. Both require authentication and have CVSS scores of 8.8.

Ivanti applied the fixes to its cloud-hosted Neurons for ITSM environments. Customers operating affected on-premises versions from the 2025.2 through 2026.1 release branches should install the relevant September 2026 security patches.

Ivanti Sentry CVE-2026-83527

Ivanti Sentry CVE-2026-83527 is a high-severity authentication bypass vulnerability rated 8.1. It affects Sentry deployments managed through EPMM or Neurons for MDM.

A remote, unauthenticated attacker could exploit the flaw to obtain administrative-level access. This potential impact makes the vulnerability especially relevant to organizations that expose Sentry to untrusted networks.

Ivanti addressed the flaw in Sentry R10.8.2, R10.7.3, and R10.6.4. Administrators should confirm their release branch and install the corresponding fixed version.

Ivanti EPMM CVE-2026-18851

Ivanti EPMM CVE-2026-18851 is a high-severity missing-authorization vulnerability rated 8.8. Unlike the Sentry flaw, it requires the attacker to authenticate before attempting exploitation.

A remote authenticated attacker could exploit the vulnerability to elevate privileges to an administrator role. Therefore, describing it simply as an authentication bypass would be misleading: the weakness affects authorization after authentication.

Ivanti fixed the flaw in EPMM 12.10.0.0, 12.9.0.2, and 12.8.0.4. Organizations running earlier builds within the affected release branches should upgrade to the appropriate fixed version.

Why this matters

ITSM, mobile management, and access gateways hold more authority than standard business applications. They may control device configurations, administrative workflows, application access, or connections to protected resources.

As a result, a flaw in the management layer can create device management risk beyond the vulnerable server itself. Administrative access could let an attacker alter configurations or interfere with security operations. Remote code execution could also affect the confidentiality, integrity, and availability of the underlying server.

Traditional endpoint controls cannot correct a vulnerability in an unpatched Ivanti product. Organizations need layered controls: vendor patching for the affected platform, restricted access to management interfaces, strong administrator authentication, least privilege, centralized logging, and monitoring for unexpected changes.

The absence of reported exploitation should not delay remediation. It only means that exploitation had not been identified when the advisories were published.

Hexnode-Unified-Endpoint-management_Brochures
Feature Resource

Why Hexnode UEM

Here's why UEM implementation might be the best thing for your organization right now

Get the Brochure

How Hexnode UEM Mitigates Admin Endpoint Risks

Hexnode UEM: Maintain a separate endpoint security baseline

Hexnode UEM helps organizations harden administrator workstations used to access Ivanti ITSM, Sentry, and EPMM consoles. Based on the device platform and management mode, administrators can enforce password requirements, encryption settings, application restrictions, and operating system update policies, helping mitigate credential theft and unauthorized console access.

Application blocklists and allowlists can limit which software users can run on supported devices. This can reduce exposure to unauthorized applications on workstations used to access privileged management consoles.

Hexnode’s policy and compliance reports can show whether assigned configurations were applied successfully and identify non-compliant endpoints. Administrators can also scan managed devices to refresh information such as installed applications, system configurations, and current compliance status. In addition, Hexnode can enforce compliance-gated network access, preventing non-compliant or unpatched administrator devices from connecting to enterprise management networks.

Audit reports provide a record of activity within the Hexnode console, including policy changes, app-management events, technician activity, and remote actions. These records can support internal reviews when security teams investigate unexpected management changes.

However, Hexnode UEM does not remediate Ivanti Sentry, EPMM, or Neurons for ITSM vulnerabilities. Organizations must still apply Ivanti’s product-specific patches and monitor the affected infrastructure. Hexnode provides an additional endpoint governance layer rather than a substitute for server patching or application security monitoring.

What security teams should do next

Start by creating an inventory of every Neurons for ITSM, Sentry, and EPMM deployment, including internally hosted instances. Record the installed release branch, exposure level, business owner, and patch status.

Apply the appropriate enterprise security patches and verify that services return to a healthy state. Where immediate patching is not possible, restrict management interfaces to trusted networks and authorized administrators. These controls reduce exposure but do not replace the vendor update.

Next, review administrator accounts, recent configuration changes, authentication records, and server logs for unexplained activity. Remove unnecessary accounts and validate that privileged users have only the access required for their roles.

Audit administrator endpoints via Hexnode UEM to enforce mandatory OS and browser patching, strict application allowlisting, and console-access baselines.

Share

Alanna River

I’m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.