External risk intelligence

Ivanti Neurons for ITSM Untrusted Data Deserialization Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-12745

Ivanti Neurons for ITSM is a management platform typically deployed as a web-based service or portal. As a central IT service management tool, it is frequently exposed to the public internet or network edge to facilitate remote access for employees and technicians, making it a service designed for connectivity.

Deserialization

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Ivanti Neurons for ITSM, potentially allowing attackers to execute code on servers. This issue stems from the handling of untrusted data during data deserialization processes.

  • Attackers can run unauthorized code on servers.
  • A critical vulnerability impacts a core IT management platform.
  • Confirming relevance and exposure is the key focus.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can reach Ivanti Neurons for ITSM via the network and send a malicious serialized payload to the application. This payload exploits a deserialization vulnerability, allowing the attacker to execute arbitrary code on the server.

  • No authentication required.
  • Sending a malicious serialized payload.
  • Arbitrary code execution on the server.

Live Threat

Current exploitation, exposure, and threat context

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM could allow a remote, unauthenticated attacker to execute arbitrary code on the server. This could impact the integrity and availability of the service when exposed to the network.

  • Server code execution.
  • Unauthenticated network access.
  • Compromised service and data.

Operational Fix

Recommended remediation, mitigation, and detection steps

Ivanti Neurons for ITSM is a critical service management platform, likely managed by an Infrastructure or Platform team, with security and network teams responsible for its exposure. The immediate priority is to identify all instances, confirm their internet reachability and business criticality, and locate the accountable owner to plan remediation according to risk.

  • Ownership: Infrastructure/Platform, Security, Network teams.
  • Verify first: Instance exposure and business criticality.
  • Action: Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Ivanti Neurons for ITSM?

Ivanti Neurons for ITSM is a centralized IT service management platform used by organizations to automate workflows, manage assets, and handle help desk requests. It functions as a web-based portal that acts as a core operational hub for IT support teams to track and resolve internal service issues across a company.

What does Deserialization of Untrusted Data mean for CVE-2026-12745?

This weakness, categorized as CWE-502, occurs when an application takes data from an untrusted source and reconstructs it into a complex object without sufficient validation. Because the software trusts this input, an attacker can craft a malicious payload that forces the application to execute arbitrary code during the process, effectively hijacking the server's operation.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted serialized payload over the network directly to the vulnerable Ivanti Neurons for ITSM application. Notably, the attacker does not need any valid user account or password to initiate this process; the system processes the malicious data automatically upon receipt.

Is my instance of Ivanti Neurons for ITSM at risk?

According to Halo Surface Signal, this software is frequently deployed as a web-based service or portal accessible over the public internet to support remote technicians. Because this CVE-2026-12745 flaw involves a network-based attack vector, any instance reachable from the internet or the network edge is considered to have a high level of exposure.

What should I do if I run this software?

First, identify every instance of Ivanti Neurons for ITSM within your environment and document their internet accessibility. Work with your infrastructure and security teams to verify the business criticality of each instance, then coordinate with the system owners to prioritize and apply the necessary updates or security mitigations provided by the vendor.

References