Multiple Ivanti Products Contain Critical Arbitrary Code Execution Vulnerabilities (CVE‑2026‑12744, CVE‑2026‑12645, etc.)
What Happened — Ivanti disclosed a set of vulnerabilities across its Endpoint Manager Mobile, Neurons for ITSM (cloud and on‑prem), and Sentry gateway products. The most severe flaws are deserialization bugs and a missing‑authorization issue that could let an unauthenticated or low‑privilege attacker execute arbitrary code on the affected server. No public exploitation has been reported to date.
Why It Matters for Trust & Control Assurance
- The scenario directly tests an organization’s vulnerability‑management control – the ability to discover, assess, and remediate critical flaws before an attacker can leverage them.
- Continuous evidence of patching and configuration compliance provides a defensible audit trail that maps to many frameworks (e.g., NIST CSF 2.0).
- Verisq’s Control Mapping capability can automatically correlate these CVEs to the relevant control objectives and surface gaps in your evidence repository.
Who Is Affected
- Large and medium enterprises using Ivanti’s endpoint‑management or ITSM suites (high risk).
- Small businesses and government agencies with lower‑tier deployments (medium risk).
Recommended Actions
- Inventory all Ivanti instances and verify version numbers against the advisory list.
- Prioritize patching for the listed CVEs; apply vendor‑released updates or mitigations immediately.
- Record the remediation steps in your control‑evidence platform to demonstrate timely vulnerability response.
- Review privileged‑account assignments on affected systems; enforce least‑privilege where possible.
Source: CIS Advisory 2026‑093
Technical Notes
- Attack vector: Exploitation of deserialization of untrusted data and missing authorization checks (remote code execution).
- CVEs: CVE‑2026‑12744, CVE‑2026‑12745, CVE‑2026‑12648, CVE‑2026‑12649, CVE‑2026‑12650, CVE‑2026‑12651, CVE‑2026‑12645, CVE‑2026‑12646.
- Potential impact: Installation of malicious programs, data alteration or deletion, depending on the compromised account’s privileges.
Source: CIS Advisory 2026‑093