SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-12645

CRITICAL · CVSS 9.9 EPSS 1.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Ivanti Neurons for ITSM versions prior to 2026.2 are vulnerable to a Missing Authorization flaw that enables remote authenticated attackers to execute arbitrary code on the server. This critical vulnerability poses significant risks, including potential data breaches and system compromise. Organizations using affected versions should prioritize immediate patching to mitigate the threat.

CVE
CVE-2026-12645
Severity
CRITICAL
CVSS
9.9
EPSS
1.23%
Ivanti

Original NVD Description

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.