📦

endpoint_manager_mobile

Vendor: ivanti

Actively Exploited 8 CISA KEV List
PoC / Exploits 6 Code Available
Total RCEs 12 Remote Access
Total CVEs 51 Total Indexed
Avg. EPSS 26.96% Exploit Prob.
Latest CVE CVE-2026-7821 May 07

Security Vulnerability Index

Page 1 / 6
7.4 CVSS

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.

EPSS: 0.51%
7.2 CVSS

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

EPSS: 34.45%
7.0 CVSS

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

EPSS: 0.82%
8.9 CVSS

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.

EPSS: 0.69%
8.8 CVSS

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

EPSS: 0.71%
9.8 CVSS
CVE-2026-1340
RCE Exploit Found

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

EPSS: 84.04%
9.8 CVSS
CVE-2026-1281
RCE Exploit Found

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

EPSS: 81.23%
4.7 CVSS

Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk.

EPSS: 0.58%
7.2 CVSS

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

EPSS: 20.84%
7.2 CVSS

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

EPSS: 20.84%