SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-12646

CRITICAL · CVSS 9.9 EPSS 1.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Ivanti Neurons for ITSM versions prior to 2026.2 are vulnerable to a Missing Authorization flaw that enables remote authenticated attackers to execute arbitrary code on the server. This critical vulnerability poses a significant risk to organizations using the affected software, as it can lead to unauthorized access and control over sensitive systems. Organizations utilizing Ivanti Neurons for ITSM should prioritize immediate patching to mitigate potential exploitation.

CVE
CVE-2026-12646
Severity
CRITICAL
CVSS
9.9
EPSS
1.19%
Ivanti

Original NVD Description

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.