DIRAS TAKE
Urgent: prioritize mitigation because all Neurons for ITSM versions are affected and no fixed release is listed; immediately restrict exposure and apply vendor guidance while awaiting a patch.
What is CVE-2026-12744?
A remote, unauthenticated attacker can execute arbitrary code on Ivanti Neurons for ITSM servers via a deserialization of untrusted data flaw tracked as CVE-2026-12744. This is a CWE-502 deserialization issue with a critical CVSS 3.1 rating indicating network access is sufficient and no privileges or user interaction are required. Vendor data lists all Neurons for ITSM versions as affected and no fixed release is provided, so attackers only need network reachability to the vulnerable service to attempt exploitation. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Ivanti Neurons for ITSM are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Neurons for ITSM | all versions |
Is CVE-2026-12744 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-12744
- Restrict network access to Neurons for ITSM interfaces; block or firewall management and service ports from untrusted networks.
- Apply any Ivanti mitigation guidance and configuration hardening that the vendor provides.
- Monitor server and application logs for indicators of code execution, unexpected process launches, and other anomalous activity.
- Isolate affected systems where feasible and prepare to deploy vendor-supplied fixes as soon as they become available.
Frequently asked questions
Is CVE-2026-12744 being actively exploited?
There are no public reports of exploitation as of 2026-09-30.
Which Neurons for ITSM versions are affected by CVE-2026-12744?
All versions of Ivanti Neurons for ITSM are listed as affected in the vendor-provided data.
Is there a patch for CVE-2026-12744?
No fixed version is listed in the provided data; a patch is not available according to the vendor information included here.
Does CVE-2026-12744 require authentication?
No, the vulnerability can be exploited by a remote unauthenticated attacker and does not require valid credentials.
References
- nvd.nist.gov/vuln/detail/CVE-2026-12744
- cve.org/CVERecord?id=CVE-2026-12744
- hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US
- All Ivanti CVEs on CVE Radar
- CVEs published in September 2026