Sceawere

Vulnerability Detail

CVE-2026-12745UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ivanti Neurons Deserialization RCE

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
Ivanti
Product
Neurons for ITSM
Attack Type
CWE-502 Deserialization of untrusted data
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-08T15:18:41.190Z",
  "pubdate": "2026-09-08T15:18:41.190Z",
  "executiveSummary": "A critical Deserialization of Untrusted Data vulnerability exists in Ivanti Neurons for ITSM versions prior to 2026.2.\nThis flaw enables a remote, unauthenticated attacker to achieve arbitrary code execution on the underlying server.\nThe vulnerability stems from improper validation of serialized objects processed by the application, allowing for the injection of malicious payloads.\nSuccessful exploitation bypasses existing authentication mechanisms, granting the attacker full system control without prior authorization.\nGiven the nature of the vulnerability, it represents a high-risk scenario for organizations utilizing Ivanti Neurons for ITSM, as it exposes the server to complete compromise, data exfiltration, and lateral movement within the network.\nThe primary risk is the complete loss of confidentiality, integrity, and availability of the affected system.",
  "technicalDetails": "The vulnerability is rooted in the insecure handling of serialized data structures within the Ivanti Neurons for ITSM framework. Applications that utilize deserialization typically convert byte streams back into objects to facilitate state management or data interchange. When an application deserializes untrusted input without sufficient validation or integrity checks, it becomes susceptible to Object Injection attacks.\nIn this specific instance, an attacker can craft a malicious serialized object containing instructions or gadget chains that execute upon instantiation during the deserialization process. By delivering this payload via a network-accessible endpoint, an unauthenticated actor can trigger the server-side logic to reconstruct the malicious object.\nThe attack flow proceeds as follows: First, the attacker identifies a network-exposed endpoint within Ivanti Neurons for ITSM that accepts serialized objects. Second, the attacker generates a payload leveraging available gadget chains present in the application's classpath or included libraries—a common technique where existing legitimate code fragments are chained together to achieve unintended outcomes. Third, the attacker transmits this payload to the vulnerable endpoint. Upon receipt, the application's deserialization routine processes the stream, inadvertently executing the embedded code.\nBecause the execution occurs within the context of the application's service account, the resulting code execution inherits the privileges of the web server process. This often results in the ability to execute system commands, manipulate application data, or deploy persistent backdoors. The vulnerability affects all versions of Ivanti Neurons for ITSM prior to 2026.2. There is no requirement for authentication, nor are there privilege prerequisites, meaning the attack surface is exposed to any network entity capable of communicating with the vulnerable service.\nPost-exploitation impact is severe, as arbitrary code execution allows an attacker to gain full control over the host. This facilitates the theft of sensitive configuration data, internal databases, and credentials cached on the system. Furthermore, this compromised node can be utilized as a pivot point to conduct further reconnaissance and lateral movement against other segments of the organization's internal infrastructure, effectively undermining the security posture of the entire managed environment."
}
CVE-2026-12745: Ivanti Neurons Deserialization RCE (CRITICAL Severity, CVSS: 9.8) | Sceawere