Ivanti patches critical Neurons for ITSM remote-code-execution flaws and fixes Sentry and EPMM authentication bugs

Ivanti released September 2026 security updates for several enterprise products, including critical flaws in Neurons for ITSM that could let attackers take over servers. The Neurons for ITSM fixes cover CVE-2026-12645, CVE-2026-12646, CVE-2026-12647, CVE-2026-12650, CVE-2026-12744, CVE-2026-12745, CVE-2026-12648, and CVE-2026-12651; CVE-2026-12744 and CVE-2026-12745 are unauthenticated. Ivanti also patched Sentry CVE-2026-83527, an unauthenticated admin-level authentication bypass, and EPMM CVE-2026-18851, an authentication bypass requiring authentication.
Why it matters: Organizations running these Ivanti products could be exposed to server takeover or admin-level access if they do not update. This looks urgent because some flaws do not require a login, so defenders should patch affected Neurons for ITSM, Sentry, and EPMM systems promptly.

Sources

Ivanti Patches Critical Flaws Across Enterprise Security Products
Ionut Arghire 2026.09.09 100% relevant
The article establishes a new patch cycle and vulnerability cluster centered on Ivanti Neurons for ITSM, plus separate newly disclosed Sentry and EPMM flaws, rather than updating one previously tracked CVE event.
← Back to all stories