Search: “Ivanti Endpoint Manager Mobile”
133 stories
2026-001: Critical vulnerabilities in Ivanti EPMM
Ivanti EPMM has two critical CVSS 9.8 flaws allowing unauthenticated remote code execution; limited exploitation has already been observed.
On 29 January 2026, Ivanti patched CVE-2026-1281 and CVE-2026-1340, two code injection vulnerabilities (both CVSS 9.8) in Endpoint Manager Mobile that allow unauthenticated remote code execution. CERT-EU reports one of the flaws was exploited in a limited number of cases. Affected versions include EPMM 12.5.1.0, 12.6.1.0 and 12.7.0.0 and prior; the permanent fix is planned for release 12.8.0.0 in Q1 2026.
Ivanti security advisory (AV26-897)
Canada's Cyber Centre relayed Ivanti's September 2026 security updates for Endpoint Manager Mobile, Neurons for ITSM, and Sentry, urging administrators to patch.
The Canadian Centre for Cyber Security forwarded Ivanti's September 2026 security updates covering Endpoint Manager Mobile, Neurons for ITSM (cloud/SaaS and on-prem), and Sentry. Affected releases include Endpoint Manager Mobile prior to 12.10.0.0, Sentry prior to R10.8.2, and Neurons for ITSM on-prem prior to 2026.2. The advisory references CVE-2026-18851 for Endpoint Manager Mobile and CVE-2026-83527 for Sentry, plus multiple CVEs in Neurons for ITSM. No exploitation is described in the advisory text.
Top 10 Best Mobile Device Management (MDM) Solutions in 2026
A 2026 MDM buyer guide ranks ten solutions, recommending Microsoft Intune for Microsoft 365 estates and Jamf for Apple-only environments.
A 2026 buyer guide evaluates ten mobile device management solutions, leading with Microsoft Intune as the default for Microsoft 365 organizations and Jamf for Apple estates. It recommends choosing the enrolment model before selecting a vendor and clarifying BYOD visibility to prevent privacy disputes. Kandji, Mosyle, Omnissa Workspace ONE, ManageEngine, Scalefusion, and Hexnode are covered as alternatives. Guidance ties MDM to Zero Trust data access policies via Apple User Enrolment and Android work profiles.
Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacks
Ivanti patched ten CVEs across EPMM, Neurons for ITSM and Sentry, including critical unauthenticated deserialization RCE; no active exploitation reported.
On September 8, 2026, Ivanti disclosed advisories covering ten CVEs in Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry. The most severe are two unauthenticated deserialization RCE flaws in Neurons for ITSM, CVE-2026-12744 and CVE-2026-12745 (CVSS 9.8), plus three missing-authorization RCE bugs rated 9.9 and three authenticated deserialization RCE flaws. EPMM has CVE-2026-18851 (CVSS 8.8), an authenticated privilege escalation flaw, and Sentry has CVE-2026-83527 (CVSS 8.1), an authentication bypass. Ivanti reports no evidence of active exploitation; cloud/SaaS ITSM was patched on August 9, 2026, while on-premises 2025.2 through 2026.1 require September 2026 patches.
Ivanti Patches 10 EPMM, Neurons for ITSM and Sentry Flaws Enabling RCE and Admin Access
Ivanti patches 10 flaws in EPMM, Neurons for ITSM, and Sentry, including two 9.8-rated unauthenticated RCEs in ITSM.
Ivanti released fixes for 10 vulnerabilities across Endpoint Manager Mobile, Neurons for ITSM, and Sentry, and said it was not aware of active exploitation at disclosure. The most severe are CVE-2026-12744 and CVE-2026-12745, unauthenticated deserialization RCEs rated 9.8 in Neurons for ITSM, alongside authenticated deserialization and missing-authorization RCEs rated up to 9.9. CVE-2026-18851 is an 8.8-rated EPMM privilege escalation to administrator, and CVE-2026-83527 is an 8.1-rated unauthenticated authentication bypass in Sentry granting administrative access. Ivanti said the ITSM weaknesses were found using large language models; Cloud/SaaS fixes shipped August 9, 2026, and on-premises patches are available from September 2026.