2026 comparison of 11 device control and USB security tools ranks CoSoSys Endpoint Protector first for cross-platform control and DLP.
An editorial scorecard evaluates eleven device control and removable-media security tools across granularity, content-aware DLP, cross-platform parity, encryption/shadowing, and value. CoSoSys Endpoint Protector (now part of Netwrix) leads at 4.60 for genuine Windows, macOS, and Linux parity, with Ivanti DeviceLock at 4.25 for the deepest Windows peripheral control and Safetica positioned for SMB and mid-market value. Enterprise content-aware DLP anchors include Symantec (Broadcom), Forcepoint, Digital Guardian (Fortra), and Trellix, with pricing almost always per endpoint.
Ivanti patches 10 flaws in EPMM, Neurons for ITSM, and Sentry, including two 9.8-rated unauthenticated RCEs in ITSM.
Ivanti released fixes for 10 vulnerabilities across Endpoint Manager Mobile, Neurons for ITSM, and Sentry, and said it was not aware of active exploitation at disclosure. The most severe are CVE-2026-12744 and CVE-2026-12745, unauthenticated deserialization RCEs rated 9.8 in Neurons for ITSM, alongside authenticated deserialization and missing-authorization RCEs rated up to 9.9. CVE-2026-18851 is an 8.8-rated EPMM privilege escalation to administrator, and CVE-2026-83527 is an 8.1-rated unauthenticated authentication bypass in Sentry granting administrative access. Ivanti said the ITSM weaknesses were found using large language models; Cloud/SaaS fixes shipped August 9, 2026, and on-premises patches are available from September 2026.
Ivanti EPMM has two critical CVSS 9.8 flaws allowing unauthenticated remote code execution; limited exploitation has already been observed.
On 29 January 2026, Ivanti patched CVE-2026-1281 and CVE-2026-1340, two code injection vulnerabilities (both CVSS 9.8) in Endpoint Manager Mobile that allow unauthenticated remote code execution. CERT-EU reports one of the flaws was exploited in a limited number of cases. Affected versions include EPMM 12.5.1.0, 12.6.1.0 and 12.7.0.0 and prior; the permanent fix is planned for release 12.8.0.0 in Q1 2026.
Unauthenticated RCE in Ivanti Endpoint Manager Mobile (EPMM)
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection flaw (CWE-94) that permits unauthenticated remote code execution: an attacker who can reach the EPMM server over the network can send crafted requests that execute arbitrary code without credentials or user interaction. Successful exploitation yields control of the MDM server, exposing directory/contact data, device inventory, and the ability to push commands or profiles to enrolled corporate mobile devices. Any organization running an affected EPMM deployment is in scope, with internet-facing instances at greatest risk; the available data does not specify affected version ranges, so operators should consult Ivanti's advisory. Exploitation is confirmed in the wild — the flaw was added to CISA's KEV on 2026-01-29 and carries an 81.8% EPSS — and press reporting describes EPMM under active zero-day attack, apparently alongside a second critical EPMM vulnerability (CVE-2026-6973), including incidents disclosed by Dutch government and EU bodies.
Unauthenticated Code Injection RCE in Ivanti Endpoint Manager Mobile
CVE-2026-1340 is a code injection flaw (CWE-94) in Ivanti Endpoint Manager Mobile (EPMM), Ivanti's enterprise mobile device management platform, that permits unauthenticated remote code execution. Because the flaw is network-reachable and requires no privileges or user interaction (AV:N/AC:L/PR:N/UI:N), a remote attacker can send a crafted request to a vulnerable EPMM server and execute arbitrary code, with high impact to confidentiality, integrity, and availability. Any organization operating an affected EPMM server is affected, especially those exposing the management or device-enrollment interface to the internet. The flaw was added to CISA's KEV catalog on 2026-04-08 with an 86.2% probability of exploitation within 30 days; news reporting describes active zero-day attacks against EPMM (alongside related CVE-2026-6973), including a confirmed Dutch government incident exposing employee contact data, while ransomware use remains unconfirmed. A large share of observed exploit traffic has been traced to a single IP address on bulletproof hosting infrastructure.
Authenticated RCE via Missing Authorization in Ivanti Neurons for ITSM
CVE-2026-12647 is a missing authorization flaw (CWE-862) in Ivanti Neurons for ITSM in versions before 2026.2, where certain requests are not properly checked against the user's permissions. A remote attacker who holds any authenticated, low-privileged account can send crafted requests that bypass the authorization check, with no user interaction required. The outcome is arbitrary code execution on the ITSM server, and the scope-changed CVSS rating indicates the impact extends beyond the vulnerable component, consistent with a full server compromise. Any organization running an affected Ivanti Neurons for ITSM deployment (on-premises or hosted) prior to 2026.2 is exposed. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at 1.2%, though it was patched alongside a batch of ten Ivanti flaws spanning EPMM, Neurons for ITSM and Sentry.
· Ivanti Neurons for ITSM all versions before 2026.2large
Authenticated Deserialization RCE in Ivanti Neurons for ITSM
Ivanti Neurons for ITSM versions before 2026.2 contain a deserialization of untrusted data flaw (CWE-502) that allows remote code execution. A remote attacker who already holds valid (low-privilege) credentials sends crafted serialized data to the server, triggering the flaw; the CVSS scope-changed rating (9.9) indicates successful exploitation affects resources beyond the vulnerable component, effectively compromising the underlying server. An attacker gains arbitrary code execution on the ITSM server, with high impact on confidentiality, integrity, and availability. Any organization running an affected version of Ivanti Neurons for ITSM is exposed, though the authentication requirement means instances that are internet-facing or that expose accounts to partners/customers carry the highest risk. As of the data available, there is no evidence of in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA KEV; EPSS estimates roughly a 1.5% chance of exploitation within 30 days (72nd percentile).
· Ivanti Neurons for ITSM all versions before 2026.2moderate
Missing Authorization Enables Authenticated RCE in Ivanti Neurons for ITSM
CVE-2026-12646 is a missing authorization flaw (CWE-862) in Ivanti Neurons for ITSM in which privileged requests are not properly permission-checked. A remote attacker holding any valid low-privilege account can send crafted network requests that bypass the authorization check and execute arbitrary code on the server; the changed scope (S:C) in the CVSS score indicates compromise can extend beyond the vulnerable component itself. Successful exploitation has critical impact on confidentiality, integrity and availability (CVSS 3.1 9.9). Any organization running Neurons for ITSM on a release before 2026.2 is affected; the fix shipped in the 2026.2 release as part of a batch of ten Ivanti patches covering EPMM, Neurons for ITSM and Sentry. Exploitation status: no known in-the-wild exploitation, no public proof-of-concept, not listed in CISA KEV, and EPSS estimates roughly a 1.2% probability of exploitation within 30 days.
· Ivanti Neurons for ITSM all versions before 2026.2moderate
Unauthenticated Deserialization RCE in Ivanti Neurons for ITSM
CVE-2026-12744 is a deserialization of untrusted data flaw (CWE-502) in Ivanti Neurons for ITSM that allows a remote, unauthenticated attacker to execute arbitrary code on the server. It is triggered by sending crafted serialized input to the network-exposed ITSM service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms the attack requires no privileges, no user interaction, and low complexity. Successful exploitation yields full server compromise, with high impact to confidentiality, integrity, and availability. All organizations running Ivanti Neurons for ITSM on any release before 2026.2 are affected, with internet-exposed or broadly reachable deployments at greatest risk. There is no known public proof-of-concept, the flaw is not yet in CISA's KEV, and EPSS estimates a 2.2% probability of exploitation within 30 days, but the patch shipped as part of a recent batch of Ivanti fixes, so defenders should treat it as a priority despite the absence of confirmed exploitation.
· Ivanti Neurons for ITSM all versions before 2026.2moderate
Unauthenticated RCE via Deserialization in Ivanti Neurons for ITSM
CVE-2026-12745 is a deserialization of untrusted data flaw (CWE-502) in Ivanti Neurons for ITSM, the vendor's enterprise IT service management platform. A remote, unauthenticated attacker can send crafted serialized data to a vulnerable instance over the network, which the server deserializes without validation. Successful exploitation results in arbitrary code execution on the server, with critical confidentiality, integrity, and availability impact (CVSS 3.1: 9.8). All deployments of Neurons for ITSM before version 2026.2 are affected, including instances published to the internet for self-service access. As of this analysis there is no known exploitation and no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 2.1% probability of exploitation within 30 days (81st percentile).
· Ivanti Neurons for ITSM all versions before 2026.2moderate
Authenticated Deserialization RCE in Ivanti Neurons for ITSM
CVE-2026-12651 is a deserialization of untrusted data flaw (CWE-502) in Ivanti Neurons for ITSM that permits a remote, authenticated attacker to execute arbitrary code on the server. It is triggered by supplying crafted serialized data to the application over the network; only low-privilege valid credentials and no user interaction are required (CVSS 3.1: 8.8, AV:N/AC:L/PR:L/UI:N). Successful exploitation yields full code execution with high impact on confidentiality, integrity, and availability on the affected server. Any organization running Ivanti Neurons for ITSM on a version earlier than 2026.2 is affected. As of publication there are no known public proof-of-concepts, it is not in CISA KEV, and no confirmed in-the-wild exploitation is reported, though EPSS assigns a 1.5% probability of exploitation within 30 days, and the fix ships as part of a broader Ivanti batch patching 10 RCE and admin-access flaws across EPMM, Neurons for ITSM, and Sentry.
· Ivanti Neurons for ITSM all versions before 2026.2moderate
Authenticated Deserialization RCE in Ivanti Neurons for ITSM
Ivanti Neurons for ITSM versions before 2026.2 contain a deserialization of untrusted data flaw (CWE-502) that lets an attacker execute arbitrary code on the server. The flaw is triggered when the application deserializes attacker-controlled data, and it can be exploited remotely by any authenticated user with low-level privileges, without user interaction. Successful exploitation yields code execution with high impact on confidentiality, integrity and availability (CVSS 3.1: 8.8). Only organizations running vulnerable, self-hosted or on-prem instances of Ivanti Neurons for ITSM are affected; Ivanti's fixed release is 2026.2. Exploitation has not been observed in the wild, no public proof-of-concept is known, and the flaw is not yet in CISA's KEV catalog, with EPSS estimating a modest ~1.5% chance of exploitation in the next 30 days.
· Ivanti Neurons for ITSM all versions before 2026.2moderate
Authentication Bypass in Ivanti Sentry Grants Remote Admin Access
CVE-2026-83527 is an authentication bypass (CWE-288) in Ivanti Sentry that allows a remote, unauthenticated attacker to gain administrative-level access to the appliance. It is triggered over the network with no prior privileges or user interaction, though the high-attack-complexity (AC:H) CVSS rating indicates exploitation depends on specific conditions rather than a trivially reliable path. A successful attacker obtains admin-level control of Sentry, the gateway component many organizations deploy alongside Ivanti EPMM/MobileIron for mobile device management, potentially exposing or disrupting device-management functions. Any organization running Ivanti Sentry on builds earlier than the fixed releases R10.8.2, R10.7.3, or R10.6.4 (depending on release line) is affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS assigns a 1.5% probability of exploitation within 30 days, so active exploitation is not currently confirmed.
· Ivanti Sentry All builds before R10.8.2, before R10.7.3, and before R10.6.4 (fixed in R10.8.2, R10.7.3, and R10.6.4, per release line)niche
Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.