Ivanti patches critical flaws in Neurons, Sentry and EPMM

Ivanti released September patches for critical and high-severity flaws in Neurons for ITSM, Sentry and Endpoint Manager Mobile; some Neurons bugs allow remote code execution and two need no authentication.

Ivanti on Tuesday released security updates that address critical and high-severity vulnerabilities in Neurons for ITSM, Sentry and Endpoint Manager Mobile (EPMM). The company rolled out the fixes as part of its September 2026 updates and said the corrections will also be included in the upcoming 2026.2 Neurons release scheduled for September 21.

Neurons for ITSM received eight fixes. Six of the defects are rated critical and could enable remote code execution. The critical flaws include missing-authorization issues tracked as CVE-2026-12647, CVE-2026-12645 and CVE-2026-12646, each with a CVSS score of 9.9. Ivanti also addressed deserialization weaknesses tracked as CVE-2026-12650 (CVSS 9.9), CVE-2026-12744 and CVE-2026-12745 (CVSS 9.8). Two additional high-severity deserialization defects, CVE-2026-12651 and CVE-2026-12648, were fixed as well. According to Ivanti’s advisory, CVE-2026-12744 and CVE-2026-12745 can be exploited without authentication.

Sentry updates R10.8.2, R10.7.3 and R10.6.4 address CVE-2026-83527, a high-severity authentication bypass that could allow unauthenticated remote actors to obtain administrative privileges. For Endpoint Manager Mobile, Ivanti released versions 12.10.0.0, 12.9.0.2 and 12.8.0.4 to remediate CVE-2026-18851, another high-severity authentication bypass; that EPMM issue requires authentication for successful exploitation.

Ivanti’s advisory urges customers running on-premises Neurons for ITSM to update to one of the resolved versions to address the vulnerabilities. The advisory also notes that the company is not aware of any of the newly disclosed vulnerabilities being exploited in the wild and that no other Ivanti products are affected. A mature vulnerability management process helps security teams prioritize unauthenticated remote-code-execution flaws affecting exposed enterprise systems.

Administrators are advised to apply the patched Neurons releases because several defects permit remote code execution and two can be triggered without valid credentials. Operators of Sentry should install the patched builds to close the authentication bypass that can grant administrative access. Ivanti recommends updating EPMM to the fixed releases.

Also this week, Citrix released updates for its Workspace app for Windows to fix two medium-severity flaws: an out-of-bounds read that requires local access and an out-of-bounds write that requires physical access to the device. Security teams managing enterprise software should review vendor advisories and apply vendor-recommended updates to reduce exposure to publicly disclosed vulnerabilities.

“Customers using the on-premises version of Ivanti Neurons for ITSM should update their solution to one of the resolved versions to address the vulnerabilities,” the advisory states.

Articles by this author