Ivanti patches critical EPMM and Sentry flaws; Canada relays September 2026 updates adding Neurons for ITSM
Ivanti patched EPMM flaws CVE-2026-1281 and CVE-2026-1340 (both CVSS 9.8, unauthenticated RCE; limited exploitation observed) on 29 January 2026, and Sentry flaws CVE-2026-10520 (CVSS 10.0, root RCE) and CVE-2026-10523 (CVSS 9.9, auth bypass) on 9 June 2026.…
CERT-EU advisories 2026-001 and 2026-008, together with a Canadian Centre for Cyber Security advisory (AV26-897), describe critical Ivanti vulnerabilities across three products. In Ivanti Endpoint Manager Mobile (EPMM), Ivanti patched on 29 January 2026 CVE-2026-1281 and CVE-2026-1340, two code injection vulnerabilities (both CVSS 9.8) that allow unauthenticated remote code execution; CERT-EU reports one of the flaws was exploited in a limited number of cases. Affected EPMM versions include 12.5.1.0, 12.6.1.0 and 12.7.0.0 and prior; the hotfix RPM does not survive version upgrades and must be reapplied, and the permanent fix is planned for release 12.8.0.0 in Q1 2026. Separately, on 9 June 2026 Ivanti released an advisory fixing two critical flaws in Ivanti Sentry versions 10.5.1 and prior, 10.6.1 and prior, and 10.7.0 and prior: CVE-2026-10520 (CVSS 10.0), an OS command injection allowing a remote unauthenticated attacker to achieve root-level RCE, and CVE-2026-10523 (CVSS 9.9), an authentication bypass letting an unauthenticated attacker create arbitrary administrative accounts and obtain full admin access; CERT-EU recommends updating Sentry appliances to fixed versions following Ivanti's guidance. In addition, on 8 September 2026 the Canadian Centre for Cyber Security forwarded Ivanti's September 2026 security updates (advisory AV26-897) covering EPMM, Neurons for ITSM (cloud/SaaS and on-prem) and Sentry, listing affected releases EPMM prior to 12.10.0.0, Sentry prior to R10.8.2 and Neurons for ITSM on-prem prior to 2026.2, and citing CVE-2026-18851 for EPMM and CVE-2026-83527 for Sentry plus multiple CVEs in Neurons for ITSM; the Canadian advisory text describes no exploitation. The sources differ on identifiers and version ranges: the Canadian advisory cites CVE-2026-18851 (EPMM) and CVE-2026-83527 (Sentry), which are not the same CVE ids as the January EPMM fixes (CVE-2026-1281/CVE-2026-1340) or the June Sentry fixes (CVE-2026-10520/CVE-2026-10523) described by CERT-EU, and it lists later version thresholds (EPMM prior to 12.10.0.0; Sentry prior to R10.8.2); the reports do not state whether the Canadian advisory covers the same flaws or a subsequent September 2026 update round.
- On 29 January 2026 Ivanti patched CVE-2026-1281 and CVE-2026-1340, two CVSS 9.8 code injection vulnerabilities in Ivanti EPMM allowing unauthenticated remote code execution (CERT-EU 2026-001).
- CERT-EU reports one of the EPMM flaws was exploited in a limited number of cases.
- Affected EPMM versions include 12.5.1.0, 12.6.1.0 and 12.7.0.0 and prior; the hotfix RPM does not survive version upgrades and must be reapplied; the permanent fix is planned in EPMM 12.8.0.0 in Q1 2026.
- On 9 June 2026 Ivanti fixed two critical Sentry flaws: CVE-2026-10520 (CVSS 10.0, OS command injection enabling unauthenticated root-level RCE) and CVE-2026-10523 (CVSS 9.9, authentication bypass enabling arbitrary admin account creation…
- Affected Sentry versions: 10.5.1 and prior, 10.6.1 and prior, and 10.7.0 and prior; fixed versions are available and CERT-EU recommends patching per Ivanti's guidance.
- The Canadian Centre for Cyber Security advisory AV26-897 (8 September 2026) relays Ivanti's September 2026 security updates covering EPMM, Neurons for ITSM (cloud/SaaS and on-prem) and Sentry, urging administrators to patch.
- AV26-897 lists affected releases: EPMM prior to 12.10.0.0, Sentry prior to R10.8.2, and Neurons for ITSM on-prem prior to 2026.2; it cites CVE-2026-18851 for EPMM, CVE-2026-83527 for Sentry, and multiple CVEs in Neurons for ITSM; no…
- Discrepancy: the Canadian advisory's CVE ids (CVE-2026-18851, CVE-2026-83527) and version thresholds differ from the CERT-EU advisories' (CVE-2026-1281/CVE-2026-1340 for EPMM; CVE-2026-10520/CVE-2026-10523 for Sentry; EPMM…
Coverage timelineoldest first · each row is one article
- · Jan 30, 20262026-001: Critical vulnerabilities in Ivanti EPMM
CERT-EU Advisories· 72
Ivanti EPMM has two critical CVSS 9.8 flaws allowing unauthenticated remote code execution; limited exploitation has already been observed.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-10520 | Unauthenticated OS Command Injection in Ivanti Sentry Ivanti Sentry (formerly MobileIron Sentry) contains an OS command injection flaw (CWE-78) that lets a remote, unauthenticated attacker execute operating-system commands with root privileges on the appliance. Exploitation succeeds when the Sentry appliance is in an unmanaged state with its endpoints externally reachable; deployments that enforce mTLS with EPMM or restrict HTTPS access through Ivanti Neurons for MDM keep the interfaces inaccessible to external actors. A successful attacker gains root-level remote code execution, giving full control of the gateway that fronts an organization's mobile device management (MDM) infrastructure. Organizations running unmanaged, internet-exposed Ivanti/MobileIron Sentry appliances are affected. The flaw is being exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-11 (formal CVSS scoring is still pending), EPSS puts the 30-day exploitation probability at 99.9%, no public proof-of-concept is known, and ransomware use is undetermined. Do: Inventory all Ivanti/MobileIron Sentry appliances and determine whether they are unmanaged with externally reachable endpoints; apply Ivanti's mitigations in line with CISA KEV and BOD 26-04 timelines, and where a patch is not yet in place, restrict access by enabling mTLS with EPMM or limiting HTTPS access through Ivanti Neurons for MDM. Monitor Ivanti's advisories for fixed versions and review exposed appliances for signs of compromise. | 10.0 | 100% | KEV |
| nichelow thousands of internet-exposed Sentry appliances (estimate; only unmanaged, externally reachable deployments are exploitable) | |
| CVE-2026-10523 | Unauthenticated Authentication Bypass in Ivanti Sentry Grants Full Admin Access CVE-2026-10523 is an authentication bypass (CWE-288) in Ivanti Sentry, the gateway component formerly known as MobileIron Sentry, affecting standalone deployments before the R10.5.2, R10.6.2, and R10.7.1 releases. A remote, unauthenticated attacker can exploit it over the network with no credentials, no user interaction, and no special conditions, creating arbitrary administrative accounts on the affected gateway. The attacker thereby obtains full administrative control of Sentry, which in most deployments sits at the network edge handling mobile-device (MDM/UEM) traffic for organizations using Ivanti's mobility management stack. Any organization running an affected standalone Sentry version is exposed, with internet-facing instances at greatest risk. Exploitation has not yet been confirmed in the wild (no public PoC, not in CISA KEV), but the high EPSS score of 51.9% (99th percentile) indicates a strong likelihood of exploitation within the next 30 days. Do: Upgrade standalone Ivanti Sentry to R10.5.2, R10.6.2, or R10.7.1 depending on your current release branch. Until patched, restrict network exposure of Sentry (especially direct internet access) and review the administrative account list for unexpected admin accounts created without authorization. Given the critical severity and high EPSS, prioritize patching internet-facing instances first. | 9.8 | 52% |
| moderate≈1,000–10,000 internet-exposed Sentry deployments (estimate) | ||
| CVE-2026-1340 +1 in the same advisory: …1281 | Unauthenticated Code Injection RCE in Ivanti Endpoint Manager Mobile CVE-2026-1340 is a code injection flaw (CWE-94) in Ivanti Endpoint Manager Mobile (EPMM), Ivanti's enterprise mobile device management platform, that permits unauthenticated remote code execution. Because the flaw is network-reachable and requires no privileges or user interaction (AV:N/AC:L/PR:N/UI:N), a remote attacker can send a crafted request to a vulnerable EPMM server and execute arbitrary code, with high impact to confidentiality, integrity, and availability. Any organization operating an affected EPMM server is affected, especially those exposing the management or device-enrollment interface to the internet. The flaw was added to CISA's KEV catalog on 2026-04-08 with an 86.2% probability of exploitation within 30 days; news reporting describes active zero-day attacks against EPMM (alongside related CVE-2026-6973), including a confirmed Dutch government incident exposing employee contact data, while ransomware use remains unconfirmed. A large share of observed exploit traffic has been traced to a single IP address on bulletproof hosting infrastructure. Do: Apply Ivanti's patched EPMM release per the vendor advisory immediately and verify the fix on any internet-facing EPMM portal; US federal agencies must follow BOD 22-01 mitigation deadlines. Until patched, restrict EPMM portal access to trusted networks/VPNs and review access logs for suspicious requests or unrecognized source IPs, noting that much exploit activity has originated from a single bulletproof-hosting IP. | 9.8 | 86% | KEV |
| large≈ tens of thousands of EPMM server deployments, a large share of them internet-exposed | |
| CVE-2026-18851 | Missing Authorization in Ivanti Endpoint Manager Mobile Allows Admin Privilege Escalation CVE-2026-18851 is a missing-authorization flaw (CWE-862) in Ivanti Endpoint Manager Mobile (EPMM) in which certain functionality fails to verify that an authenticated user is authorized to perform administrative actions. A remote attacker who already holds a valid low-privilege session can send crafted requests over the network, with no user interaction required, and escalate to administrator. From an admin position, the attacker gains full control of the mobile device management console, including access to managed-device data and the ability to alter or push configurations to enrolled devices. Organizations running EPMM versions before 12.10.0.0, 12.9.0.2, or 12.8.0.4 are affected. As of the advisory there is no known in-the-wild exploitation and no public proof-of-concept, it is not in CISA KEV (EPSS ~1.0%), and it was patched as part of a larger Ivanti batch covering EPMM, Neurons for ITSM and Sentry flaws enabling RCE and admin access. Do: Upgrade EPMM to 12.10.0.0, 12.9.0.2, or 12.8.0.4 depending on the release branch in use, per Ivanti's advisory. Until patched, restrict EPMM console/API interfaces to trusted networks and review logs for authenticated users performing unexpected administrative actions. Because this fix ships in the same batch as other EPMM, Neurons for ITSM and Sentry patches, apply the full set of vendor updates rather than only this CVE. | 8.8 | 1% |
| massplausibly >1,000,000 managed devices/users across tens of thousands of enterprise and government deployments | ||
| CVE-2026-83527 | Authentication Bypass in Ivanti Sentry Grants Remote Admin Access CVE-2026-83527 is an authentication bypass (CWE-288) in Ivanti Sentry that allows a remote, unauthenticated attacker to gain administrative-level access to the appliance. It is triggered over the network with no prior privileges or user interaction, though the high-attack-complexity (AC:H) CVSS rating indicates exploitation depends on specific conditions rather than a trivially reliable path. A successful attacker obtains admin-level control of Sentry, the gateway component many organizations deploy alongside Ivanti EPMM/MobileIron for mobile device management, potentially exposing or disrupting device-management functions. Any organization running Ivanti Sentry on builds earlier than the fixed releases R10.8.2, R10.7.3, or R10.6.4 (depending on release line) is affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS assigns a 1.5% probability of exploitation within 30 days, so active exploitation is not currently confirmed. Do: Upgrade Ivanti Sentry to R10.8.2 (or R10.7.3 / R10.6.4 for the corresponding release line) as addressed in Ivanti's advisory AV26-897. Until patched, minimize Sentry's internet exposure to required management/enrollment traffic and review appliance logs for unexpected administrator logins. Ivanti EPMM and Neurons for ITSM administrators should also review the same advisory, which covers additional flaws in those products. | 8.1 | 1% |
| nichelikely low-thousands of deployments, with only a few hundred internet-exposed instances in past public scans |