SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12648

HIGH · CVSS 8.8 EPSS 1.46%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Ivanti Neurons for ITSM versions prior to 2026.2 are vulnerable to a deserialization of untrusted data flaw, enabling remote authenticated attackers to execute arbitrary code on the server. This high-severity vulnerability poses significant risks to the integrity and confidentiality of affected systems. Organizations using this software should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-12648
Severity
HIGH
CVSS
8.8
EPSS
1.46%
Ivanti

Original NVD Description

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.