CVE-2026-5787Disclosure(ivanti / endpoint_manager_mobile)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch ivanti endpoint_manager_mobile systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager_mobile

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 4 mentions (2026-05-08); latest day: 2
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
endpoint_manager_mobile

2 versions affected across 1 product

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-05-07: 1Mentions · 2026-05-08: 4Mentions · 2026-05-13: 1Mentions · 2026-05-20: 1Mentions · 2026-06-07: 2Active Exploitation · 2026-05-08: 2Patch / Workaround · 2026-05-08: 3Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 3Technical Details · 2026-05-13: 1Technical Details · 2026-05-20: 1Technical Details · 2026-06-07: 105-0705-0805-1305-2006-07
Signal classification4 categories
Disclosure
444.4%
Patch
222.2%
General
222.2%
Active Exploitation
111.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-071
Disclosure1
2026-05-084
Active Exploitation1Disclosure1Patch2
2026-05-131
Disclosure1
2026-05-201
General1
2026-06-072
Disclosure1General1
Full discourse9 posts
  • Cytex@cytexsmb
    Patch

    🚨 Ivanti EPMM Zero-Day Under Attack Ivanti has disclosed a new security vulnerability in Endpoint Manager Mobile that is being exploited in limited attacks. The flaw, tracked as CVE-2026-6973 with a CVSS score of 7.2, allows a remotely authenticated user with administrative access to execute code on the system. Successful exploitation requires valid admin credentials, meaning attackers must already have access before using this flaw. The Vulnerability 🔴 CVE-2026-6973 – CVSS 7.2. Improper input validation in EPMM versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1. Remote authenticated user with admin access can achieve remote code execution. Attacker must already have administrative credentials. 📜 Critical Context Ivanti recommended in January that customers rotate credentials if they were exploited with CVE-2026-1281 and CVE-2026-1340. Organizations that followed that guidance have significantly reduced risk. The attacker needs admin access; credential rotation blocks the prerequisite. Exploitation Status Limited attacks observed in the wild. Unknown who is behind the exploitation. Unknown end goals of the attacks. US CISA Action Added to Known Exploited Vulnerabilities catalog. Federal agencies must apply fixes by May 10, 2026. 🩹 Additional Patched Flaws CVE-2026-5786 (CVSS 8.8): Improper access control allowing remote authenticated attacker to gain admin access. CVE-2026-5787 (CVSS 8.9): Improper certificate validation allowing unauthenticated attacker to impersonate Sentry hosts and obtain valid CA-signed client certificates. CVE-2026-5788 (CVSS 7.0): Improper access control allowing unauthenticated attacker to invoke arbitrary methods. CVE-2026-7821 (CVSS 7.4): Improper certificate validation allowing unauthenticated attacker to enroll restricted devices, leading to information disclosure. 🛡️ Mitigations Apply available security patches to all EPMM on-premises instances immediately. Monitor Apache access logs for signs of attempted or successful exploitation. Implement network segmentation to restrict EPMM administrative interfaces to trusted networks only. Review and harden mobile device management policies. This RCE requires admin privileges. The January credential rotation advice directly reduces exposure. Organizations that did not rotate credentials remain at higher risk.

    Post summary

    CVE‑2026‑6973 is a remote code execution flaw actively exploited in limited attacks; Ivanti recommends patching and credential rotation to mitigate the risk.

    12130140
    851 followersView on X
  • Cytex@cytexsmb
    Patch

    Ivanti CVE-2026-6973 is an RCE flaw, but it requires administrative access to exploit. The attacker must already have valid admin credentials before they can use this vulnerability. That means credential theft or prior compromise is a prerequisite, not an outcome of this bug. What the vulnerability actually does: Allows a remote authenticated user with admin access to execute code on the EPMM server. Improper input validation leads to remote code execution. Affects EPMM versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1. Why credential rotation matters more than patching in this case: Ivanti advised customers in January to rotate credentials if they were exploited with two earlier CVEs (CVE-2026-1281 and CVE-2026-1340). Organizations that rotated credentials have significantly reduced risk for the new flaw: CVE-2026-6973. Without valid admin credentials, an attacker cannot use this RCE. CISA added to KEV. Federal agencies must patch by May 10, 2026. Four additional vulnerabilities were fixed alongside this RCE: CVE-2026-5786 (CVSS 8.8): Authenticated attacker gains admin access. CVE-2026-5787 (CVSS 8.9): Unauthenticated attacker impersonates Sentry hosts and obtains valid certificates. CVE-2026-5788 (CVSS 7.0): Unauthenticated attacker invokes arbitrary methods. CVE-2026-7821 (CVSS 7.4): Unauthenticated attacker enrolls restricted devices leading to information disclosure. The pattern: Two of the additional flaws (CVE-2026-5787 and CVE-2026-5788) are unauthenticated. An attacker could use those to gain initial access, then use CVE-2026-6973 to escalate to RCE. The chain is the real threat, not the individual vulnerability. As AI-driven tooling becomes more embedded in security processes, customers should expect an increase in vulnerability disclosures. The defensive priority: Patch all five vulnerabilities together. Rotate credentials if you have not done so since January. Assume that unauthenticated flaws (CVE-2026-5787 and CVE-2026-5788) may have been used to obtain the admin credentials required for CVE-2026-6973.

    Post summary

    The post details Ivanti’s CVE‑2026‑6973 remote code execution flaw, stresses the necessity of credential rotation and patching, and lists related vulnerabilities, but offers no PoC or active exploitation evidence.

    11010117
    840 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-5787 — CVSS 8.9 | High Priority — Unauthenticated Type: Improper Certificate Validation Authentication required: None Impact: Impersonate registered Sentry hosts → obtain valid CA-signed client certificates

    Post summary

    A high‑priority Sentry certificate‑validation flaw is disclosed; no PoC, exploit, or patch details are provided.

    1000024
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    8, 2026 — The Device Manager Is Compromised: Ivanti EPMM's Five-CVE Zero-Day Bundle and the January Credential Domino. Published: May 8, 2026 | Category: CVE Deep Dive | Severity: Critical CVEs: CVE-2026-6973 · CVE-2026-5786 · CVE-2026-5787 · CVE-2026-5788 · CVE-2026-7821

    Post summary

    The article announces a set of five critical zero‑day CVEs for Ivanti EPMM but does not provide technical details, exploits, or mitigation information.

    1000036
    253 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-5787: Improper Certificate Validation in Ivanti EPMM - What It Means for Your Business and How to Respond https://hubs.li/Q04hhdRK0

    Post summary

    The text announces a vulnerability (Improper Certificate Validation) but provides only basic information without details on PoC, exploitation, or mitigation.

    0000055
    31 followersView on X
  • Polsia@polsia
    Disclosure

    CVE-2026-5787 affects Ivanti EPMM. CVSS 8.9. Certificate validation flaw lets unauthenticated attackers impersonate hosts. ThreatForge detected certificate substitution risk. Identity systems at risk. https://threatforge-l929.polsia.app

    Post summary

    CVE‑2026‑5787 is a certificate‑validation flaw in Ivanti EPMM, rated CVSS 8.9, that allows unauthenticated attackers to impersonate hosts, with ThreatForge noting a certificate substitution risk.

    0000048
    19.9K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Two critical Ivanti EPMM bugs CVE-2026-5787 and CVE-2026-5788 allow remote unauthenticated attacks, no patches yet for versions before 12.6.1.1, 12.7.0.1, 12.8.0.1. https://threatcluster.io/cluster/critical-vulnerabilities-in-ivanti-epmm-expose-systems-to-re-9288c287

    Post summary

    Two critical Ivanti EPMM bugs, CVE‑2026‑5787 and CVE‑2026‑5788, have been disclosed and enable remote unauthenticated attacks; currently no patches exist for affected versions before 12.6.1.1, 12.7.0.1, or 12.8.0.1.

    0000045
    221 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Ivanti Endpoint Manager Mobile (CVE-2026-5787) https://vuldb.com/vuln/361895/cti

    Post summary

    CTI team reports observed activity targeting CVE‑2026‑5787 in Ivanti Endpoint Manager Mobile, indicating active exploitation in the wild.

    0000048
    2.1K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-5787 An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unau… CVSS 8.9 Full analysis → https://sec.kaitan.id/cves/CVE-2026-5787 #Ivanti #CyberSecurity #InfoSec

    Post summary

    Announces the discovery of CVE-2026-5787, an improper certificate validation flaw in Ivanti EPMM, providing a CVSS score and a link to a full analysis.

    0000050
    515 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager_mobile---
Appivantiendpoint_manager_mobile12.7.0.0--
Appivantiendpoint_manager_mobile12.8.0.0--

Explore more