Ivanti has announced a series of security advisories affecting three of its core enterprise products: Endpoint Manager Mobile, Neurons for ITSM, and Sentry. These vulnerabilities, disclosed on September 8, 2026, span ten distinct CVEs and pose significant risks including privilege escalation and remote code execution. The severity of these vulnerabilities is underscored by several critical ratings, impacting a broad range of Ivanti’s mobile device management and IT service management solutions.
The most pressing concern within these disclosures is a high-severity missing authorization flaw, identified as CVE-2026-18851, in Ivanti Endpoint Manager Mobile. This vulnerability, which scores a CVSS of 8.8, allows remote authenticated attackers to gain full administrative access. Affected versions include 12.9.0.1 and earlier, 12.8.0.3 and earlier, and all builds prior to 12.10.0.0. Ivanti has released updates to mitigate this risk, with fixed versions now available.
Ivanti Neurons for ITSM is also heavily impacted, with eight CVEs revealed. Three of these carry a critical risk rating of 9.9. Notably, CVE-2026-12744 and CVE-2026-12745 involve deserialization of untrusted data, allowing unauthenticated attackers to execute arbitrary code on the server. Additional vulnerabilities require authentication but still permit remote code execution, all rating extremely high in severity. Ivanti has credited advanced large language models integrated into its security workflows for identifying these vulnerabilities, a unique instance of AI-assisted discovery.
For Neurons for ITSM, cloud and SaaS versions have already been patched as of August 9, 2026. On-premises users running versions 2025.2 through 2026.1 must apply the September 2026 security patches, with version 2026.2 set to release on September 21.
Lastly, CVE-2026-83527 affects Ivanti Sentry systems managed via EPMM and Neurons for MDM. This authentication bypass vulnerability, rated 8.1, allows unauthenticated remote attackers to obtain administrative access. Fixed releases for this flaw are now available. Despite no evidence of active exploitation prior to these disclosures, Ivanti advises immediate patching, especially for Neurons for ITSM instances that are exposed to the internet.

