CVE-2026-12744
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execu
CVSS
9.8
Critical
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-502
Not enough EPSS history yet.
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-813858.8 HIG—
———Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.4hCVE-2026-774848.8 HIG—
———Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.3hCVE-2026-696947.0 HIG—
———Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.4hCVE-2026-657728.8 HIG—
———Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.4hCVE-2026-472978.1 HIG—
———Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.4hCVE-2026-127459.8 CRI—
———A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.6h