Executive brief
Ivanti Endpoint Manager Mobile (formerly MobileIron Core) is a platform used by organizations to manage and secure mobile devices. A critical vulnerability has been identified that allows an unauthorized person to remotely execute commands on the management server over the internet. This could lead to a total compromise of the mobile device management system, allowing attackers to steal sensitive data or disrupt mobile operations. This vulnerability is currently being exploited in the wild.
Technical details
A code injection vulnerability (CWE-94) exists in Ivanti Endpoint Manager Mobile (EPMM) due to improper control of the generation of code. The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the server to execute arbitrary code. The vulnerability is reachable over the network without user interaction. Ivanti has released patches for affected versions, and CISA has added this to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation. Affected versions include those up to and including 12.7.0.0.
Affected products
- Ivanti Endpoint Manager Mobile (EPMM) Up to and including 12.7.0.0
Timeline
- 2026-01-29: disclosed
- 2026-01-29: advisory
- 2026-01-29: kev added: Added to CISA KEV catalog due to active exploitation.
- 2026-01-29: exploited
- 2026-01-29: patched: Vendor advisory and patches released.