CVE-2026-12744
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execu
CVSS
9.8
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 8 sept 2026 · Última mod.: 8 sept 2026 · CWE-502
Sin historial EPSS suficiente todavía.
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-813858.8 ALT—
———Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.4hCVE-2026-774848.8 ALT—
———Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.4hCVE-2026-696947.0 ALT—
———Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.4hCVE-2026-657728.8 ALT—
———Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.4hCVE-2026-472978.1 ALT—
———Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.4hCVE-2026-127459.8 CRÍ—
———A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.7h