Description:
Ivanti has released security advisories to address the vulnerabilities in Ivanti products. Detailed information about the vulnerabilities can be found at:
https://forums.ivanti.com/s/article/kA1UL0000009oLl0AI
https://forums.ivanti.com/s/article/kA1UL0000009ovF0AQ
https://forums.ivanti.com/s/article/kA1UL0000009oK90AI
Affected Systems:
- Ivanti Endpoint Manager Mobile (EPMM) versions 12.8.0.3 and prior
- Ivanti Endpoint Manager Mobile (EPMM) versions 12.9.0.1 and prior
- Ivanti Neurons for ITSM (Cloud / SaaS) versions 2026.2
- Ivanti Neurons for ITSM On-Prem versions 2025.2, 2025.3, 2025.4, 2026.1
- Ivanti Sentry versions R10.6.3 and prior
- Ivanti Sentry versions R10.7.2 and prior
- Ivanti Sentry versions R10.8.1 and prior
For detailed information of the affected systems, please refer to the corresponding security advisories at vendor's website.
Impact:
Successful exploitation of the vulnerabilities could lead to remote code execution, elevation of privilege or security restriction bypass on an affected system.
Recommendation:
Patches for affected systems are available. System administrators of affected systems should follow the recommendations provided by the vendor and take immediate actions to mitigate the risk.
More Information:
- https://forums.ivanti.com/s/article/kA1UL0000009oK90AI
- https://forums.ivanti.com/s/article/kA1UL0000009oLl0AI
- https://forums.ivanti.com/s/article/kA1UL0000009ovF0AQ
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12645 (to CVE-2026-12648)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12650 (to CVE-2026-12651)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12744 (to CVE-2026-12745)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-18851
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-83527