ELEVATED 6 min read 20 Sep 2026

Multiple vulnerabilities in Ivanti Neurons Leads Today's Security Review

Threat Level: Elevated Tags: cve-2026-12645, cve-2026-12646, cwe-862, cve-2026-27238, cwe-122, cve-2026-86520, cve-2026-86689, cve-2026-77960, cwe-798, cve-2026-28326

Key findings
01
Multiple vulnerabilities in Ivanti Neurons
CRITICAL
CVE coverage: CVE-2026-12645, CVE-2026-12646. A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
02
InDesign Desktop: Heap-based Buffer Overflow
HIGH
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
03
Multiple vulnerabilities in Bransys ELD
HIGH
Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) iOS <1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960).
04
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
HIGH
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.
05
Multiple vulnerabilities in EMX Tecnologia Gestao X
HIGH
CVE coverage: CVE-2026-79418, CVE-2026-79419. The cited advisories disclose: Business Suite 8.4 and earlier.
06
n8n: Exposure of Resource to Wrong Sphere
MEDIUM
n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and 2.32.1), a user able to run a Code node could poison a cached module and thereby alter other users' Code-node executions on the same runner, affecting their confidentiality, integrity, or availability.
07
Intel Transfer Learning Tool: Protection Mechanism Failure
MEDIUM
Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege.

Executive assessment

Today's brief leads with Multiple vulnerabilities in Ivanti Neurons. All 7 selected findings retain their own technical scope, action, observed status, and evidence limits.

Panel synthesis: Finding 01 leads because it is critical, has fixed versions listed for Cloud/SaaS and on-premises deployments, and includes an explicit interim control to remove internet exposure until patched. Patch order: Finding 01 (Critical Ivanti Neurons vulnerabilities with listed fixed versions and a clear control to remove on-premises internet exposure until a resolved version is installed); Finding 05 (High EMX Tecnologia Gestao X vulnerabilities with proof-of-concept exploitation and no fixed version listed, making the stated CSP and cookie controls the immediate action); Finding 04 (High SolarWinds ARM hard-coded key flaw enabling unauthenticated RCE, with version 2026.2.1 listed as fixed and network restriction controls provided); Finding 02 (High InDesign heap-based vulnerability with fixed Windows and macOS releases and controls for blocking or quarantining untrusted InDesign documents).

Also today: 5 more n8n CVEs (CVE-2026-72762, CVE-2026-72772, CVE-2026-72767, CVE-2026-72769, CVE-2026-85169) in the same disclosure wave as the n8n card of 2026-09-11; none reported exploited; carried as a note rather than a finding.

Finding 01 — Multiple vulnerabilities in Ivanti Neurons

What changed: CVE coverage: CVE-2026-12645, CVE-2026-12646. A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Technical evidence: CVE-2026-12645; CVSS v3.1 9.9; weakness CWE-862; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: For on-premises deployments, remove internet exposure until a resolved version is installed. ([hub.ivanti.com](https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US))

Fix: Cloud/SaaS 2026.2; on-premises the September 2026 Security Patch for 2025.2, 2025.3, 2025.4 or 2026.1, or version 2026.2. ([hub.ivanti.com](https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US))

Action: Map CVE-2026-12645 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-12645)

Finding 02 — InDesign Desktop: Heap-based Buffer Overflow

What changed: InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Technical evidence: CVE-2026-27238; CVSS v3.1 7.8; weakness CWE-122; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Block or quarantine InDesign documents from untrusted external sources, and filter .indd, .indt and .idml email attachments. Run InDesign as a non-privileged user. Adobe reports that it is not aware of any exploits in the wild for the issues addressed by APSB26-32. ([helpx.adobe.com](https://helpx.adobe.com/security/products/indesign/apsb26-32.html), [sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27238/), [cisecurity.org](https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2026-034))

Affected: Adobe InDesign ID21.2 and earlier, and ID20.5.2 and earlier, on Windows and macOS. ([helpx.adobe.com](https://helpx.adobe.com/security/products/indesign/apsb26-32.html))

Fix: Adobe InDesign ID21.3 and ID20.5.3 for Windows and macOS. ([helpx.adobe.com](https://helpx.adobe.com/security/products/indesign/apsb26-32.html))

Panel assessment: Patch this week where InDesign is in use: exploitation needs a user to open a malicious file, but successful code execution runs as that user, so the blast radius is the user’s accessible documents, credentials and publishing assets rather than the application alone. (priority: this week)

Action: Map CVE-2026-27238 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-27238)

Finding 03 — Multiple vulnerabilities in Bransys ELD

What changed: Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) iOS <1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960).

Technical evidence: CVE-2026-86520; CVSS v3.1 7.5; weakness CWE-798; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: CISA recommends minimising network exposure, placing systems and remote devices behind firewalls, and isolating them from business networks. Where remote access is required, use an up-to-date VPN. CISA reports that no known public exploitation specifically targeting these vulnerabilities has been reported to it. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01))

Fix: Android 11.00.00 or newer; iOS 1.1.54 or newer. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01))

Panel assessment: Patch this week: the issue is high severity because hard-coded credentials and cleartext transmission can enable unauthorised access, but the record says there is no known public exploitation, so this is not an emergency patch-now case. The likely path is use of embedded credentials or interception of sensitive traffic to reach telemetry data and firmware, making this a fleet-data and device-integrity risk rather than a generic enterprise compromise finding. (priority: this week)

Action: Map CVE-2026-86520 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01)

Finding 04 — SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

What changed: SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system.

Technical evidence: CVE-2026-28326; CVSS v3.1 8.8; weakness CWE-321; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Use IP whitelisting to restrict ARM ports, and keep ARM on a dedicated server that is neither public nor internet-facing. The Hacker News reports that SolarWinds makes no mention of the vulnerability being exploited in the wild. ([documentation.solarwinds.com](https://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htm), [thehackernews.com](https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html), [solarwinds.com](https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28326))

Fix: SolarWinds Access Rights Manager 2026.2.1 ([solarwinds.com](https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28326))

Action: Map CVE-2026-28326 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: thehackernews.com](https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html)

Finding 05 — Multiple vulnerabilities in EMX Tecnologia Gestao X

What changed: CVE coverage: CVE-2026-79418, CVE-2026-79419. The cited advisories disclose: Business Suite 8.4 and earlier.

Technical evidence: CVE-2026-79418; CVSS v3.1 8.7; weakness CWE-79; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Apply Content Security Policy (CSP) to restrict unwanted script execution, and enable Secure and HttpOnly cookie flags. Miggo reports proof-of-concept exploitation for both CVEs. ([drive.google.com](https://drive.google.com/file/d/1mp-uS-tAthH9FAObfx1D3lOM7IIjRsmE/view?usp=sharing), [drive.google.com](https://drive.google.com/file/d/1QVH1MRo3G4KqmBORkhXITzcYmO_BDjWc/view), [miggo.io](https://www.miggo.io/vulnerability-database/cve/CVE-2026-79418), +1 more)

Action: Map CVE-2026-79418 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-79418)

Finding 06 — n8n: Exposure of Resource to Wrong Sphere

What changed: n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and 2.32.1), a user able to run a Code node could poison a cached module and thereby alter other users' Code-node executions on the same runner, affecting their confidentiality, integrity, or availability.

Technical evidence: CVE-2026-72764; CVSS v4.0 5.8; weakness CWE-668; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Restrict n8n access to fully trusted users and disable built-in and external modules by unsetting NODE_FUNCTION_ALLOW_BUILTIN and NODE_FUNCTION_ALLOW_EXTERNAL. Where supported, use external runner mode with a dedicated runner per user or project. ([github.com](https://github.com/n8n-io/n8n/security/advisories/GHSA-9cmh-xcqm-5hqr), [sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-72764/))

Affected: n8n versions earlier than 1.123.67, 2.31.5, and 2.32.1. ([github.com](https://github.com/n8n-io/n8n/security/advisories/GHSA-9cmh-xcqm-5hqr))

Fix: n8n versions 1.123.67, 2.31.5, and 2.32.1. ([github.com](https://github.com/n8n-io/n8n/security/advisories/GHSA-9cmh-xcqm-5hqr))

Action: Map CVE-2026-72764 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-72764)

Finding 07 — Intel Transfer Learning Tool: Protection Mechanism Failure

What changed: Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege.

Technical evidence: CVE-2026-39452; CVSS v4.0 6.3; weakness CWE-693; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Uninstall Intel Transfer Learning Tool or discontinue its use as soon as possible. ([intel.com](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01499.html))

Fix: No fixed version is available; Intel is not releasing updates to mitigate the vulnerability. ([intel.com](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01499.html))

Action: Map CVE-2026-39452 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-39452)

cve-2026-12645cve-2026-12646cve-2026-27238cve-2026-28326cve-2026-39452cve-2026-72764cve-2026-77960cve-2026-79418cve-2026-86520cve-2026-86689

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.