CVE-2026-5788Disclosure(ivanti / endpoint_manager_mobile)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch ivanti endpoint_manager_mobile systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager_mobile

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-08); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
endpoint_manager_mobile

2 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-07: 1Mentions · 2026-05-08: 3Mentions · 2026-06-07: 1Active Exploitation · 2026-05-08: 1Patch / Workaround · 2026-05-08: 3Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 305-0705-0806-07
Signal classification4 categories
Disclosure
240.0%
Active Exploitation
120.0%
Patch
120.0%
General
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-071
Disclosure1
2026-05-083
Active Exploitation1Disclosure1Patch1
2026-06-071
General1
Full discourse5 posts
  • Cytex@cytexsmb
    Active Exploitation

    🚨 Ivanti EPMM Zero-Day Under Attack Ivanti has disclosed a new security vulnerability in Endpoint Manager Mobile that is being exploited in limited attacks. The flaw, tracked as CVE-2026-6973 with a CVSS score of 7.2, allows a remotely authenticated user with administrative access to execute code on the system. Successful exploitation requires valid admin credentials, meaning attackers must already have access before using this flaw. The Vulnerability 🔴 CVE-2026-6973 – CVSS 7.2. Improper input validation in EPMM versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1. Remote authenticated user with admin access can achieve remote code execution. Attacker must already have administrative credentials. 📜 Critical Context Ivanti recommended in January that customers rotate credentials if they were exploited with CVE-2026-1281 and CVE-2026-1340. Organizations that followed that guidance have significantly reduced risk. The attacker needs admin access; credential rotation blocks the prerequisite. Exploitation Status Limited attacks observed in the wild. Unknown who is behind the exploitation. Unknown end goals of the attacks. US CISA Action Added to Known Exploited Vulnerabilities catalog. Federal agencies must apply fixes by May 10, 2026. 🩹 Additional Patched Flaws CVE-2026-5786 (CVSS 8.8): Improper access control allowing remote authenticated attacker to gain admin access. CVE-2026-5787 (CVSS 8.9): Improper certificate validation allowing unauthenticated attacker to impersonate Sentry hosts and obtain valid CA-signed client certificates. CVE-2026-5788 (CVSS 7.0): Improper access control allowing unauthenticated attacker to invoke arbitrary methods. CVE-2026-7821 (CVSS 7.4): Improper certificate validation allowing unauthenticated attacker to enroll restricted devices, leading to information disclosure. 🛡️ Mitigations Apply available security patches to all EPMM on-premises instances immediately. Monitor Apache access logs for signs of attempted or successful exploitation. Implement network segmentation to restrict EPMM administrative interfaces to trusted networks only. Review and harden mobile device management policies. This RCE requires admin privileges. The January credential rotation advice directly reduces exposure. Organizations that did not rotate credentials remain at higher risk.

    Post summary

    CVE-2026-6973 is a CVSS 7.2 remote code execution flaw in Ivanti EPMM, actively exploited in limited attacks, requiring admin credentials, and mitigated by patching and credential rotation.

    12130140
    851 followersView on X
  • Cytex@cytexsmb
    Patch

    Ivanti CVE-2026-6973 is an RCE flaw, but it requires administrative access to exploit. The attacker must already have valid admin credentials before they can use this vulnerability. That means credential theft or prior compromise is a prerequisite, not an outcome of this bug. What the vulnerability actually does: Allows a remote authenticated user with admin access to execute code on the EPMM server. Improper input validation leads to remote code execution. Affects EPMM versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1. Why credential rotation matters more than patching in this case: Ivanti advised customers in January to rotate credentials if they were exploited with two earlier CVEs (CVE-2026-1281 and CVE-2026-1340). Organizations that rotated credentials have significantly reduced risk for the new flaw: CVE-2026-6973. Without valid admin credentials, an attacker cannot use this RCE. CISA added to KEV. Federal agencies must patch by May 10, 2026. Four additional vulnerabilities were fixed alongside this RCE: CVE-2026-5786 (CVSS 8.8): Authenticated attacker gains admin access. CVE-2026-5787 (CVSS 8.9): Unauthenticated attacker impersonates Sentry hosts and obtains valid certificates. CVE-2026-5788 (CVSS 7.0): Unauthenticated attacker invokes arbitrary methods. CVE-2026-7821 (CVSS 7.4): Unauthenticated attacker enrolls restricted devices leading to information disclosure. The pattern: Two of the additional flaws (CVE-2026-5787 and CVE-2026-5788) are unauthenticated. An attacker could use those to gain initial access, then use CVE-2026-6973 to escalate to RCE. The chain is the real threat, not the individual vulnerability. As AI-driven tooling becomes more embedded in security processes, customers should expect an increase in vulnerability disclosures. The defensive priority: Patch all five vulnerabilities together. Rotate credentials if you have not done so since January. Assume that unauthenticated flaws (CVE-2026-5787 and CVE-2026-5788) may have been used to obtain the admin credentials required for CVE-2026-6973.

    Post summary

    Ivanti CVE-2026-6973 is a remote code execution flaw that requires administrative credentials; patch all five related vulnerabilities and rotate credentials to mitigate risk, with no evidence of active exploitation.

    11010117
    840 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    8, 2026 — The Device Manager Is Compromised: Ivanti EPMM's Five-CVE Zero-Day Bundle and the January Credential Domino. Published: May 8, 2026 | Category: CVE Deep Dive | Severity: Critical CVEs: CVE-2026-6973 · CVE-2026-5786 · CVE-2026-5787 · CVE-2026-5788 · CVE-2026-7821

    Post summary

    The brief announcement lists five CVEs but provides no details about proofs of concept, exploit code, active exploitation, patches, or technical specifics.

    1000036
    253 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Two critical Ivanti EPMM bugs CVE-2026-5787 and CVE-2026-5788 allow remote unauthenticated attacks, no patches yet for versions before 12.6.1.1, 12.7.0.1, 12.8.0.1. https://threatcluster.io/cluster/critical-vulnerabilities-in-ivanti-epmm-expose-systems-to-re-9288c287

    Post summary

    Two critical Ivanti EPMM vulnerabilities (CVE-2026-5787 and CVE-2026-5788) enable remote unauthenticated attacks, with no patches currently available for older releases.

    0000045
    221 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-5788 An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthentica… CVSS 7.0 Full analysis → https://sec.kaitan.id/cves/CVE-2026-5788 #Ivanti #CyberSecurity #InfoSec

    Post summary

    This post discloses a high‑severity improper access control vulnerability (CVE‑2026‑5788) in specific Ivanti EPMM versions, providing CVSS score and linking to a full analysis.

    0000040
    515 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager_mobile---
Appivantiendpoint_manager_mobile12.7.0.0--
Appivantiendpoint_manager_mobile12.8.0.0--

Explore more