CVE-2026-5786Patch(ivanti / endpoint_manager_mobile)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch ivanti endpoint_manager_mobile systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager_mobile

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-05-08); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
endpoint_manager_mobile

2 versions affected across 1 product

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-05-07: 1Mentions · 2026-05-08: 2Mentions · 2026-05-10: 2Mentions · 2026-05-11: 1Mentions · 2026-06-07: 1Mentions · 2026-06-10: 1Active Exploitation · 2026-05-08: 1Patch / Workaround · 2026-05-08: 2Patch / Workaround · 2026-05-10: 2Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 2Technical Details · 2026-05-10: 105-0705-0805-1005-1106-0706-10
Signal classification4 categories
Patch
337.5%
General
337.5%
Disclosure
112.5%
Active Exploitation
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-071
Disclosure1
2026-05-082
Active Exploitation1Patch1
2026-05-102
Patch2
2026-05-111
General1
2026-06-071
General1
2026-06-101
General1
Full discourse8 posts
  • Cytex@cytexsmb
    Active Exploitation

    🚨 Ivanti EPMM Zero-Day Under Attack Ivanti has disclosed a new security vulnerability in Endpoint Manager Mobile that is being exploited in limited attacks. The flaw, tracked as CVE-2026-6973 with a CVSS score of 7.2, allows a remotely authenticated user with administrative access to execute code on the system. Successful exploitation requires valid admin credentials, meaning attackers must already have access before using this flaw. The Vulnerability 🔴 CVE-2026-6973 – CVSS 7.2. Improper input validation in EPMM versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1. Remote authenticated user with admin access can achieve remote code execution. Attacker must already have administrative credentials. 📜 Critical Context Ivanti recommended in January that customers rotate credentials if they were exploited with CVE-2026-1281 and CVE-2026-1340. Organizations that followed that guidance have significantly reduced risk. The attacker needs admin access; credential rotation blocks the prerequisite. Exploitation Status Limited attacks observed in the wild. Unknown who is behind the exploitation. Unknown end goals of the attacks. US CISA Action Added to Known Exploited Vulnerabilities catalog. Federal agencies must apply fixes by May 10, 2026. 🩹 Additional Patched Flaws CVE-2026-5786 (CVSS 8.8): Improper access control allowing remote authenticated attacker to gain admin access. CVE-2026-5787 (CVSS 8.9): Improper certificate validation allowing unauthenticated attacker to impersonate Sentry hosts and obtain valid CA-signed client certificates. CVE-2026-5788 (CVSS 7.0): Improper access control allowing unauthenticated attacker to invoke arbitrary methods. CVE-2026-7821 (CVSS 7.4): Improper certificate validation allowing unauthenticated attacker to enroll restricted devices, leading to information disclosure. 🛡️ Mitigations Apply available security patches to all EPMM on-premises instances immediately. Monitor Apache access logs for signs of attempted or successful exploitation. Implement network segmentation to restrict EPMM administrative interfaces to trusted networks only. Review and harden mobile device management policies. This RCE requires admin privileges. The January credential rotation advice directly reduces exposure. Organizations that did not rotate credentials remain at higher risk.

    Post summary

    The post reports that CVE-2026-6973 is actively exploited, provides patching and credential‑rotation guidance, and details the RCE risk, urging urgent action for Ivanti EPMM users.

    12130140
    851 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High - Ivanti EPMM Multiple Vulnerabilities (CVE-2026-6973, CVE-2026-5786 & more) High-severity flaws in Ivanti EPMM allow remote attackers to gain administrative access, impersonate hosts, and execute arbitrary code. By exploiting improper input validation and missing access controls, attackers can bypass authorization mechanisms, leading to full host compromise (RCE). 👉 Upgrade immediately to the patched version for your branch (12.6.1.1, 12.7.0.1, or 12.8.0.1) https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US

    Post summary

    The advisory announces multiple high‑severity CVEs in Ivanti EPMM, highlights RCE risks via input validation flaws, and urges users to upgrade to patched versions.

    00030121
    255 followersView on X
  • Cytex@cytexsmb
    Patch

    Ivanti CVE-2026-6973 is an RCE flaw, but it requires administrative access to exploit. The attacker must already have valid admin credentials before they can use this vulnerability. That means credential theft or prior compromise is a prerequisite, not an outcome of this bug. What the vulnerability actually does: Allows a remote authenticated user with admin access to execute code on the EPMM server. Improper input validation leads to remote code execution. Affects EPMM versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1. Why credential rotation matters more than patching in this case: Ivanti advised customers in January to rotate credentials if they were exploited with two earlier CVEs (CVE-2026-1281 and CVE-2026-1340). Organizations that rotated credentials have significantly reduced risk for the new flaw: CVE-2026-6973. Without valid admin credentials, an attacker cannot use this RCE. CISA added to KEV. Federal agencies must patch by May 10, 2026. Four additional vulnerabilities were fixed alongside this RCE: CVE-2026-5786 (CVSS 8.8): Authenticated attacker gains admin access. CVE-2026-5787 (CVSS 8.9): Unauthenticated attacker impersonates Sentry hosts and obtains valid certificates. CVE-2026-5788 (CVSS 7.0): Unauthenticated attacker invokes arbitrary methods. CVE-2026-7821 (CVSS 7.4): Unauthenticated attacker enrolls restricted devices leading to information disclosure. The pattern: Two of the additional flaws (CVE-2026-5787 and CVE-2026-5788) are unauthenticated. An attacker could use those to gain initial access, then use CVE-2026-6973 to escalate to RCE. The chain is the real threat, not the individual vulnerability. As AI-driven tooling becomes more embedded in security processes, customers should expect an increase in vulnerability disclosures. The defensive priority: Patch all five vulnerabilities together. Rotate credentials if you have not done so since January. Assume that unauthenticated flaws (CVE-2026-5787 and CVE-2026-5788) may have been used to obtain the admin credentials required for CVE-2026-6973.

    Post summary

    The post details Ivanti CVE‑2026‑6973 as an RCE that requires admin credentials, stresses the need for patching and credential rotation, and lists related vulnerabilities and mitigation steps.

    11010117
    840 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    8, 2026 — The Device Manager Is Compromised: Ivanti EPMM's Five-CVE Zero-Day Bundle and the January Credential Domino. Published: May 8, 2026 | Category: CVE Deep Dive | Severity: Critical CVEs: CVE-2026-6973 · CVE-2026-5786 · CVE-2026-5787 · CVE-2026-5788 · CVE-2026-7821

    Post summary

    The article mentions a five‑CVE zero‑day bundle targeting Ivanti EPMM with a critical severity rating but provides no further technical, exploit, patch, or mitigation details.

    1000036
    253 followersView on X
  • Login Sécurité@LoginSecurite
    General

    🚨 Alerte sécurité : CVE-2026-5786, 5787 et 5788 dans Ivanti EPMM 🚨 Une fois ces vulnérabilités exploitées, l’attaquant aura ainsi accès à l’application en tant qu’administrateur. Plus d'informations : https://login-securite.com/alertes/fr-vulnerabilites-critiques-dans-ivanti-epmm

    Post summary

    The alert notes the presence of CVEs in Ivanti EPMM and that exploitation would grant administrator access, but it provides no technical, POC, or mitigation details.

    00010115
    544 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-5786: Ivanti EPMM Access Control Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04kMW2J0

    Post summary

    The brief title indicates a discussion of Ivanti EPMM’s access control bug, but provides no concrete technical details, exploits, or mitigation steps.

    0000029
    31 followersView on X
  • ToolsLib@ToolsLib
    Patch

    Ivanti EPMM updates address multiple flaws (CVE-2026-5786/5787/5788/6973/7821) https://blog.toolslib.net/2026/05/10/ivanti-epmm-may-2026-cves/

    Post summary

    The blog post announces Ivanti EPMM patches that address five CVEs, but provides no proof of concept, exploit details, or evidence of active exploitation.

    0000065
    543 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-5786 An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remot… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-5786 #Ivanti #CyberSecurity #InfoSec

    Post summary

    The post announces CVE-2026-5786 as an Improper Access Control flaw in Ivanti EPMM, with a CVSS score of 8.8, but does not provide a PoC, exploit code, active exploitation reports, or patch information.

    0000045
    515 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager_mobile---
Appivantiendpoint_manager_mobile12.7.0.0--
Appivantiendpoint_manager_mobile12.8.0.0--

Explore more