NCSC-2026-0358 [1.00] [M/H] Kwetsbaarheden verholpen in Ivanti Neurons for ITSM
Ivanti heeft meerdere kwetsbaarheden verholpen in Ivanti Neurons for ITSM. Een kwaadwillende kan de kwetsbaarheden misbruiken om ongeautoriseerde acties uit te voeren, waaronder het uitvoeren van willekeurige code op de server.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0358
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-126451.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-126461.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 66% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-126471.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 66% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-126481.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 72% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-126501.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 72% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-126511.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 72% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-127442.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 81% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-127452.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 81% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-12645 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12646 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12647 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12648 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12650 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12651 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12744 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12745 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEU] [hoch] Ivanti Neurons for ITSM: Mehrere Schwachstellen ermöglichen Codeausführungcert-bund
- criticalCVE-2026-12745: A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 all…nvd
- criticalCVE-2026-12744: A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 all…nvd
- highCVE-2026-12651: A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 all…nvd
- criticalCVE-2026-12650: A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 all…nvd
- highCVE-2026-12648: A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 all…nvd
- criticalCVE-2026-12647: A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote…nvd
- criticalCVE-2026-12646: A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote…nvd
- criticalCVE-2026-12645: A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote…nvd
Recent advisories for Kwetsbaarheden verholpen in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN productenncsc-nl · 2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustratorncsc-nl · 2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Managerncsc-nl · 2026-09-09
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusionncsc-nl · 2026-09-09
- unknownNCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commercencsc-nl · 2026-09-09
- unknownNCSC-2026-0360 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Photoshop Desktopncsc-nl · 2026-09-09
More from NCSC-NL Advisories
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustrator2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager2026-09-09
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion2026-09-09
- unknownNCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commerce2026-09-09