Summary
- Ivanti's September security cycle covers Neurons for ITSM, Endpoint Manager Mobile and Sentry.
- Several ITSM vulnerabilities can allow authenticated remote attackers to execute arbitrary code and carry CVSS scores of 9.9.
- Ivanti says it has no evidence that the September vulnerabilities are being exploited in the wild.
Ivanti has released September security updates for vulnerabilities across Neurons for ITSM, Endpoint Manager Mobile and Sentry, including critical flaws that can lead to remote code execution.
The updates cover both cloud and on-premises versions of Neurons for ITSM as well as Ivanti’s enterprise mobile-management and access-control products. Canada’s Cyber Centre issued an advisory on 8 September directing administrators to review Ivanti’s updates and apply the necessary fixes.
Among the most serious issues are missing-authorisation vulnerabilities in Neurons for ITSM. CVE-2026-12645 and CVE-2026-12646 each carry CVSS v3.1 scores of 9.9 and can allow a remote authenticated attacker to execute arbitrary code on the server in affected versions.
Ivanti has also addressed vulnerabilities in Endpoint Manager Mobile and Sentry, with affected-version ranges extending across several supported branches. Cloud instances of Neurons for ITSM have received the relevant security update, while on-premises customers need the applicable September security patch or a fixed product version.
Ivanti says it has no evidence that the vulnerabilities disclosed in its September cycle are being exploited in the wild. That distinction is important given the company’s history of vulnerabilities becoming targets for active campaigns: the available evidence supports a serious patching story, not a claim that the newly disclosed flaws are already being used in attacks.
The technical severity remains substantial because enterprise IT-management platforms operate with privileges that ordinary applications do not require. A service-management server may integrate with directories, ticketing workflows, administrative systems and automation tooling, increasing the value of server-side code execution once an attacker has obtained the access required by the vulnerability.
The same principle applies across mobile-management technology. Products such as EPMM and Sentry sit in the path between user devices and enterprise resources, so authentication and authorisation defects can affect the layer responsible for enforcing access policy rather than an isolated endpoint.
This concentration of authority is why administrative platforms repeatedly attract scrutiny when critical vulnerabilities are published. Organisations may have strong controls around business applications while leaving management interfaces accessible to privileged users, service accounts and integration systems across the estate.
Ivanti’s release also reflects the growing role of automated analysis in product-security programmes. The company says it has incorporated multiple large language models into engineering and product-security testing and that some flaws disclosed in the current cycle were identified through those processes before being validated by human reviewers.
The use of AI in vulnerability discovery does not alter the remediation obligation. The operational questions remain which affected versions are deployed, whether vulnerable interfaces are exposed beyond their intended administrative boundary and how quickly fixes can be introduced without disrupting the systems they manage.
The September release spans multiple product lines rather than a single weakness, making asset identification especially important. An organisation that uses one Ivanti platform cannot assume the update applies identically to another, and the fixed version varies between products and branches.
With no confirmed exploitation, the available remediation window remains preventative rather than incident-driven. That window can narrow quickly once technical details are public, particularly for enterprise-management software that offers attackers a high-value position after compromise.





