DIRAS TAKE
Urgent: the issue affects all versions and there is currently no patch available, so prioritize reducing exposure of Neurons for ITSM to untrusted networks and applying compensating controls immediately.
What is CVE-2026-12745?
An unauthenticated remote attacker can execute arbitrary code on Ivanti Neurons for ITSM servers via a deserialization flaw; this is tracked as CVE-2026-12745. All versions of Neurons for ITSM are listed as affected. The vulnerability requires no prior authentication or user interaction and can be triggered remotely by sending crafted data to the affected service. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Ivanti Neurons for ITSM are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Neurons for ITSM | all versions |
Is CVE-2026-12745 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-12745
- Isolate Neurons for ITSM instances from the public internet and restrict access to trusted management networks.
- Apply network-level controls such as IP allowlists, VPNs, or firewall rules to limit incoming traffic to required hosts and ports.
- Monitor server and application logs for anomalous activity and indicators of exploitation, and increase logging where possible.
- Follow Ivanti vendor guidance and apply any updates or mitigations the vendor publishes as soon as they become available.
Frequently asked questions
Is CVE-2026-12745 being actively exploited?
There are no public reports of exploitation of CVE-2026-12745 as of 2026-09-30.
Which Neurons for ITSM versions are affected by CVE-2026-12745?
All versions of Ivanti Neurons for ITSM are listed as affected.
Is there a patch for CVE-2026-12745?
No patch is available according to the provided facts; administrators should apply network mitigations and follow vendor guidance until a fix is released.
Does CVE-2026-12745 require authentication?
No, CVE-2026-12745 can be exploited without authentication against Ivanti Neurons for ITSM.
References
- nvd.nist.gov/vuln/detail/CVE-2026-12745
- cve.org/CVERecord?id=CVE-2026-12745
- hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US
- All Ivanti CVEs on CVE Radar
- CVEs published in September 2026