Executive brief
Ivanti Endpoint Manager Mobile (EPMM), a platform used by organizations to manage and secure mobile devices, contains a critical vulnerability. This flaw allows an unauthenticated attacker to remotely execute malicious code on the system over the network. Successful exploitation could lead to a complete takeover of the management server, potentially compromising all managed mobile devices and sensitive corporate data.
Technical details
A code injection vulnerability (CWE-94) exists in Ivanti Endpoint Manager Mobile (EPMM) versions up to and including 12.7.0.0. The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the application to execute arbitrary code. This is a network-based attack that requires no user interaction or prior privileges. The vulnerability has been observed being exploited in the wild, and Ivanti has released security advisories and mitigations to address the issue.
Affected products
- Ivanti Endpoint Manager Mobile (EPMM) Up to and including 12.7.0.0
Timeline
- 2026-01-29: disclosed: Initial CVE publication and vendor advisory release
- 2026-04-08: kev added: CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog