Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026091401094848 | Publication Time | 2026-09-14 13:22:48 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-14 13:22:48 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Ivanti Neurons for ITSM Contains Eight High-Risk Security Vulnerabilities |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000010 ITSM is a reliable and powerful IT service management solution from Ivanti that helps organizations improve service efficiency and ensure compliance and security in IT operations. Recently, Ivanti issued a critical cybersecurity advisory for Ivanti Neurons for ITSM, which contains eight high-risk security vulnerabilities. CVE-2026-12744 (CVSS: 9.8) is a Deserialization of Untrusted Data vulnerability that allows an unauthenticated remote attacker to execute arbitrary code on the server. CVE-2026-12745 (CVSS: 9.8) is a Deserialization of Untrusted Data vulnerability that allows an unauthenticated remote attacker to execute arbitrary code on the server. CVE-2026-12651 (CVSS: 8.8) is a Deserialization of Untrusted Data vulnerability that allows an authenticated remote attacker to execute arbitrary code on the server. CVE-2026-12650 (CVSS: 9.9) is a Deserialization of Untrusted Data vulnerability that allows an authenticated remote attacker to execute arbitrary code on the server. CVE-2026-12648 (CVSS: 8.8) is a Deserialization of Untrusted Data vulnerability that allows an authenticated remote attacker to execute arbitrary code on the server. CVE-2026-12645 (CVSS: 9.9) is a Missing Authorization vulnerability that allows an authenticated remote attacker to execute arbitrary code on the server. CVE-2026-12646 (CVSS: 9.9) is a Missing Authorization vulnerability that allows an authenticated remote attacker to execute arbitrary code on the server. CVE-2026-12647 (CVSS: 9.9) is a Missing Authorization vulnerability that allows an authenticated remote attacker to execute arbitrary code on the server. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
Ivanti Neurons for ITSM (Cloud / SaaS) version 2026.2 |
|||
|
[Recommended Actions] Please update to the following versions: Ivanti Neurons for ITSM (Cloud / SaaS) mo2026.2 or later
|
|||
|
[Reference] |
|||