📦

endpoint_manager_mobile

Vendor: ivanti

Actively Exploited 8 CISA KEV List
PoC / Exploits 6 Code Available
Total RCEs 12 Remote Access
Total CVEs 48 Total Indexed
Avg. EPSS 23.41% Exploit Prob.
Latest CVE CVE-2026-7821 May 07

Security Vulnerability Index

Page 1 / 5
7.4 CVSS

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.

EPSS: 0.06%
7.2 CVSS

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

EPSS: 4.91%
7.0 CVSS

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

EPSS: 0.25%
8.9 CVSS

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.

EPSS: 0.06%
8.8 CVSS

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

EPSS: 0.39%
9.8 CVSS
CVE-2026-1340
RCE Exploit Found

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

EPSS: 69.72%
9.8 CVSS
CVE-2026-1281
RCE Exploit Found

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

EPSS: 81.59%
4.7 CVSS

Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk.

EPSS: 0.73%
7.2 CVSS

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

EPSS: 9.23%
7.2 CVSS

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

EPSS: 9.23%