ZeroHour

Vulnerabilities

496 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-18851
Missing Authorization in Ivanti Endpoint Manager Mobile Allows Admin Privilege Escalation

CVE-2026-18851 is a missing-authorization flaw (CWE-862) in Ivanti Endpoint Manager Mobile (EPMM) in which certain functionality fails to verify that an authenticated user is authorized to perform administrative actions. A remote attacker who already holds a valid low-privilege session can send crafted requests over the network, with no user interaction required, and escalate to administrator. From an admin position, the attacker gains full control of the mobile device management console, including access to managed-device data and the ability to alter or push configurations to enrolled devices. Organizations running EPMM versions before 12.10.0.0, 12.9.0.2, or 12.8.0.4 are affected. As of the advisory there is no known in-the-wild exploitation and no public proof-of-concept, it is not in CISA KEV (EPSS ~1.0%), and it was patched as part of a larger Ivanti batch covering EPMM, Neurons for ITSM and Sentry flaws enabling RCE and admin access.

Do: Upgrade EPMM to 12.10.0.0, 12.9.0.2, or 12.8.0.4 depending on the release branch in use, per Ivanti's advisory. Until patched, restrict EPMM console/API interfaces to trusted networks and review logs for authenticated users performing unexpected administrative actions. Because this fix ships in the same batch as other EPMM, Neurons for ITSM and Sentry patches, apply the full set of vendor updates rather than only this CVE.

8.81%
  • Ivanti Endpoint Manager Mobile (EPMM) All versions before 12.10.0.0, 12.9.0.2, and 12.8.0.4 (each supported release branch); fixed in 12.10.0.0, 12.9.0.2, and 12.8.0.4
massplausibly >1,000,000 managed devices/users across tens of thousands of enterprise and government deployments
CVE-2026-14903
+1 in the same advisory: …14902
Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.

Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.

NVD description · AI analysis pending
6.5
group max
1%
  • ivanti xtraction
CVE-2026-10523
Unauthenticated Authentication Bypass in Ivanti Sentry Grants Full Admin Access

CVE-2026-10523 is an authentication bypass (CWE-288) in Ivanti Sentry, the gateway component formerly known as MobileIron Sentry, affecting standalone deployments before the R10.5.2, R10.6.2, and R10.7.1 releases. A remote, unauthenticated attacker can exploit it over the network with no credentials, no user interaction, and no special conditions, creating arbitrary administrative accounts on the affected gateway. The attacker thereby obtains full administrative control of Sentry, which in most deployments sits at the network edge handling mobile-device (MDM/UEM) traffic for organizations using Ivanti's mobility management stack. Any organization running an affected standalone Sentry version is exposed, with internet-facing instances at greatest risk. Exploitation has not yet been confirmed in the wild (no public PoC, not in CISA KEV), but the high EPSS score of 51.9% (99th percentile) indicates a strong likelihood of exploitation within the next 30 days.

Do: Upgrade standalone Ivanti Sentry to R10.5.2, R10.6.2, or R10.7.1 depending on your current release branch. Until patched, restrict network exposure of Sentry (especially direct internet access) and review the administrative account list for unexpected admin accounts created without authorization. Given the critical severity and high EPSS, prioritize patching internet-facing instances first.

9.852%
  • Ivanti Sentry (standalone) All standalone Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1 (i.e., each release branch R10.5.x, R10.6.x, and R10.7.x before its respective fixed relea
moderate≈1,000–10,000 internet-exposed Sentry deployments (estimate)
CVE-2026-10520
Unauthenticated OS Command Injection in Ivanti Sentry

Ivanti Sentry (formerly MobileIron Sentry) contains an OS command injection flaw (CWE-78) that lets a remote, unauthenticated attacker execute operating-system commands with root privileges on the appliance. Exploitation succeeds when the Sentry appliance is in an unmanaged state with its endpoints externally reachable; deployments that enforce mTLS with EPMM or restrict HTTPS access through Ivanti Neurons for MDM keep the interfaces inaccessible to external actors. A successful attacker gains root-level remote code execution, giving full control of the gateway that fronts an organization's mobile device management (MDM) infrastructure. Organizations running unmanaged, internet-exposed Ivanti/MobileIron Sentry appliances are affected. The flaw is being exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-11 (formal CVSS scoring is still pending), EPSS puts the 30-day exploitation probability at 99.9%, no public proof-of-concept is known, and ransomware use is undetermined.

Do: Inventory all Ivanti/MobileIron Sentry appliances and determine whether they are unmanaged with externally reachable endpoints; apply Ivanti's mitigations in line with CISA KEV and BOD 26-04 timelines, and where a patch is not yet in place, restrict access by enabling mTLS with EPMM or limiting HTTPS access through Ivanti Neurons for MDM. Monitor Ivanti's advisories for fixed versions and review exposed appliances for signs of compromise.

10.0100% KEV
  • Ivanti Sentry (formerly MobileIron Sentry)
nichelow thousands of internet-exposed Sentry appliances (estimate; only unmanaged, externally reachable deployments are exploitable)
CVE-2026-8992
An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.

NVD description · AI analysis pending
8.8<1%
  • ivanti secure access client
CVE-2026-8111
+2 in the same advisory: …8110 …8109
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.

NVD description · AI analysis pending
8.8
group max
7%
  • ivanti endpoint manager
CVE-2026-8051
OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code

OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

NVD description · AI analysis pending
7.22%
  • ivanti virtual traffic manager
CVE-2026-8043
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTM

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.

NVD description · AI analysis pending
9.6<1%
  • ivanti xtraction
CVE-2026-7432
+1 in the same advisory: …7431
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

NVD description · AI analysis pending
7.0
group max
<1%
  • ivanti secure access client
CVE-2026-5788
+3 in the same advisory: …5787 …7821 …5786
An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

NVD description · AI analysis pending
9.8
group max
<1%
  • ivanti endpoint manager mobile
CVE-2026-6973
Authenticated RCE in Ivanti Endpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation flaw (CWE-20) that allows a remotely authenticated user with administrative access to achieve remote code execution on the server. An attacker triggers it by sending crafted input to the EPMM management interface after authenticating with administrative credentials, so compromise or misuse of an admin account is the likely path to exploitation. Successful exploitation yields code execution on the EPMM server, giving an attacker a foothold in the organization's mobile device management infrastructure and potential access to data managed through it. Any organization running Ivanti EPMM, typically enterprises using it as their MDM platform, is affected; the available data does not specify affected version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-07, confirming active exploitation (ransomware use unknown), and it carries a high 34.5% EPSS for exploitation in the next 30 days.

Do: Update EPMM to the patched release identified in Ivanti's advisory, as required under CISA KEV and BOD 22-01 for federal agencies. Until patched, restrict and audit administrative access to EPMM, review authentication and admin-activity logs for signs of abuse, and limit exposure of the management interface to trusted networks.

7.234% KEV
  • Ivanti Endpoint Manager Mobile (EPMM)
largetens of thousands of EPMM deployments worldwide
CVE-2026-3483
An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.

An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.

NVD description · AI analysis pending
7.8<1%
  • ivanti desktop \& server management
CVE-2026-1603
Authentication Bypass in Ivanti Endpoint Manager Leaks Stored Credentials

CVE-2026-1603 is an authentication bypass (CWE-288/CWE-306) in Ivanti Endpoint Manager (EPM) that affects versions before 2024 SU5. A remote, unauthenticated attacker can send crafted network requests to a vulnerable EPM core server without valid credentials. Successful exploitation grants read access to specific stored credential data held by EPM, which could be leveraged for further access within the environment. Any organization running an EPM deployment on a version earlier than 2024 SU5 is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-09, confirming active exploitation in the wild, and its EPSS score of 80.6% (100th percentile) indicates a very high likelihood of exploitation in the next 30 days; no public proof-of-concept is known, suggesting private exploit use.

Do: Upgrade EPM core servers to version 2024 SU5 (or later) as soon as possible, in line with CISA's KEV and BOD 22-01 timelines, which have been shortened for this flaw. Until patched, restrict internet-facing exposure of EPM services and review EPM servers for anomalous authentication activity or signs of stored-credential access. If mitigations are unavailable, follow CISA's guidance to apply vendor-recommended mitigations or discontinue use of the affected product.

7.581% KEV
  • Ivanti Endpoint Manager (EPM) all versions before 2024 SU5
largetens of thousands of EPM core-server deployments (order of 10,000–100,000 installations), an estimate
CVE-2026-1602
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

NVD description · AI analysis pending
6.5<1%
  • ivanti endpoint manager
CVE-2026-1340
+1 in the same advisory: …1281
Unauthenticated Code Injection RCE in Ivanti Endpoint Manager Mobile

CVE-2026-1340 is a code injection flaw (CWE-94) in Ivanti Endpoint Manager Mobile (EPMM), Ivanti's enterprise mobile device management platform, that permits unauthenticated remote code execution. Because the flaw is network-reachable and requires no privileges or user interaction (AV:N/AC:L/PR:N/UI:N), a remote attacker can send a crafted request to a vulnerable EPMM server and execute arbitrary code, with high impact to confidentiality, integrity, and availability. Any organization operating an affected EPMM server is affected, especially those exposing the management or device-enrollment interface to the internet. The flaw was added to CISA's KEV catalog on 2026-04-08 with an 86.2% probability of exploitation within 30 days; news reporting describes active zero-day attacks against EPMM (alongside related CVE-2026-6973), including a confirmed Dutch government incident exposing employee contact data, while ransomware use remains unconfirmed. A large share of observed exploit traffic has been traced to a single IP address on bulletproof hosting infrastructure.

Do: Apply Ivanti's patched EPMM release per the vendor advisory immediately and verify the fix on any internet-facing EPMM portal; US federal agencies must follow BOD 22-01 mitigation deadlines. Until patched, restrict EPMM portal access to trusted networks/VPNs and review access logs for suspicious requests or unrecognized source IPs, noting that much exploit activity has originated from a single bulletproof-hosting IP.

9.886% KEV
  • Ivanti Endpoint Manager Mobile (EPMM)
large≈ tens of thousands of EPMM server deployments, a large share of them internet-exposed
CVE-2025-13659
+3 in the same advisory: …13661 …13662 …10573
Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to wri

Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.

NVD description · AI analysis pending
8.8
group max
2%
  • ivanti endpoint manager
CVE-2025-10918
Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anyw

Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk

NVD description · AI analysis pending
7.1<1%
  • ivanti endpoint manager
CVE-2025-10985
+3 in the same advisory: …10243 …10242 …10986
Authenticated OS Command Injection RCE in Ivanti Endpoint Manager Mobile (EPMM)

CVE-2025-10985 is an operating system command injection flaw (CWE-78) in the admin panel of Ivanti Endpoint Manager Mobile (EPMM), an enterprise mobile device management product. An attacker who has already authenticated to the admin panel with administrator credentials can submit a crafted request that injects and runs arbitrary operating system commands on the EPMM server, achieving full remote code execution with high impact on confidentiality, integrity, and availability. Because administrator privileges are required, practical risk concentrates where an admin account is compromised, a privileged user is malicious, or the admin console is reachable from untrusted networks, and a successful attacker takes over the MDM server and, with it, the mobile fleet it manages. Organizations running EPMM on the 12.4, 12.5, or 12.6 branches prior to the fixed releases (12.4.0.4, 12.5.0.4, and 12.6.0.2) are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS rates a 20.8% probability of exploitation within 30 days (97th percentile).

Do: Upgrade EPMM to version 12.6.0.2, 12.5.0.4, or 12.4.0.4 to match your installed branch. Because exploitation requires authenticated administrator access, enforce MFA and strong credentials on the EPMM admin console, restrict admin-panel access to trusted networks or a VPN, and review admin accounts and application logs for signs of compromise. EPMM has been targeted by in-the-wild attacks before (the 2023 EPMM RCEs), so prioritize patching even though no exploitation of this CVE is currently reported.

7.2
group max
21%
  • Ivanti Endpoint Manager Mobile (EPMM) All 12.6.x releases prior to 12.6.0.2
  • Ivanti Endpoint Manager Mobile (EPMM) All 12.5.x releases prior to 12.5.0.4
  • Ivanti Endpoint Manager Mobile (EPMM) All 12.4.x releases prior to 12.4.0.4
largetens of thousands of EPMM deployments (~2,000-3,000 internet-exposed; millions of managed devices in aggregate)
CVE-2025-9713
Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution.

Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

NVD description · AI analysis pending
8.8
group max
15%
  • ivanti endpoint manager
CVE-2025-9712
+1 in the same advisory: …9872
Unauthenticated RCE via Filename Validation Flaw in Ivanti Endpoint Manager

CVE-2025-9712 is a remote code execution vulnerability in Ivanti Endpoint Manager caused by insufficient filename validation (CWE-434), meaning files with crafted or unsafe names are not properly checked by the product. A remote, unauthenticated attacker can trigger the flaw over the network, but exploiting it requires some user interaction (CVSS:3.1 AV:N/AC:L/PR:N/UI:R, score 8.8 High). Successful exploitation gives the attacker code execution with high impact on confidentiality, integrity, and availability on the affected Endpoint Manager installation. Organizations running Ivanti Endpoint Manager 2024 before SU3 SR1 or the 2022 line before SU8 SR2 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but EPSS assigns a 20.5% probability of exploitation within 30 days (97th percentile), indicating elevated near-term risk.

Do: Upgrade Ivanti Endpoint Manager 2024 to SU3 SR1 (or later) and Endpoint Manager 2022 to SU8 SR2 (or later). Restrict network access to the Endpoint Manager server from untrusted networks and check whether any EPM services are internet-exposed. Given the user-interaction requirement and elevated EPSS, brief administrators on unexpected file-download prompts and monitor the server for anomalous process activity.

8.821%
  • Ivanti Endpoint Manager 2024 all versions before 2024 SU3 SR1
  • Ivanti Endpoint Manager 2022 all versions before 2022 SU8 SR2
largeon the order of tens of thousands of Ivanti EPM server deployments (10,000s of installations; each manages many more endpoints)
CVE-2025-8712
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivant

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure restricted settings.

NVD description · AI analysis pending
5.4<1%
  • ivanti neurons for secure access
  • ivanti connect secure
  • ivanti policy secure
  • +1 more
CVE-2025-55148
+1 in the same advisory: …8711
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure restricted settings.

NVD description · AI analysis pending
7.6
group max
<1%
  • ivanti connect secure
  • ivanti policy secure
  • ivanti zero trust access gateway
  • +1 more