Ivanti Patches Critical Flaws Across Enterprise Security Products
Ivanti has released security updates to address a significant number of critical and high-severity vulnerabilities across its Neurons for ITSM, Sentry, and EPMM products. These flaws could allow remote code execution and unauthorized access, with some requiring no authentication to exploit. The company urges customers to update immediately to mitigate the risks.
Ivanti announced on Tuesday the release of security updates to address a substantial collection of critical and high-severity vulnerabilities within its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) products. Neurons for ITSM received the most extensive set of fixes, with six critical-severity issues potentially leading to remote code execution. These included CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646 (CVSS score of 9.9/10), described as missing authorization issues; and CVE-2026-12650, CVE-2026-12744, and CVE-2026-12745 (CVSS score of 9.8/10), described as deserialization of untrusted data weaknesses. The remaining two bugs, tracked as CVE-2026-12651 and CVE-2026-12648, are high-severity deserialization of untrusted data defects also leading to remote code execution. Only CVE-2026-12744 and CVE-2026-12745 can be exploited without authentication. Updates were released for Neurons for ITSM versions 2025.2, 2025.3, 2025.4, and 2026.1, and will be included in version 2026.2 scheduled for September 21. Ivanti also released Sentry versions R10.8.2, R10.7.3, and R10.6.4 with patches for CVE-2026-83527, a high-severity authentication bypass that could allow remote, unauthenticated attackers to gain administrative privileges. EPMM versions 12.10.0.0, 12.9.0.2, and 12.8.0.4 were released to resolve CVE-2026-18851, another high-severity authentication bypass. Unlike the Sentry bug, this one requires authentication for successful exploitation. Ivanti states it is not aware of any of these vulnerabilities being exploited in the wild, and notes that no other Ivanti products are affected. Citrix also announced fixes for two medium-severity flaws in its Workspace app for Windows: an out-of-bounds read that requires local access, and an out-of-bounds write that requires physical access to an affected system.