<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Ivanti</title><description>Actively exploited vulnerabilities affecting Ivanti products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/ivanti.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-10520 — Ivanti Sentry OS Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-10520</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-10520</guid><description>This critical flaw in Ivanti Sentry allows a remote attacker with no credentials to execute commands as root — the highest privilege level on the system. Because Sentry acts as a mobile device management gateway, a full compromise could expose MDM infrastructure and the devices it manages. The risk is highest when the appliance is unmanaged and its interfaces are publicly reachable. Deployments using mTLS with EPMM or restricted HTTPS access through Neurons for MDM have those interfaces shielded from external attackers.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>Ivanti</category><category>Sentry</category></item><item><title>CVE-2026-6973 — Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-6973</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-6973</guid><description>This vulnerability in Ivanti Endpoint Manager Mobile allows an authenticated administrator-level attacker to remotely execute arbitrary code on the system. While requiring admin credentials raises the bar slightly, compromised admin accounts — through phishing or credential theft — are a realistic threat vector. EPMM is a mobile device management platform, meaning a successful exploit could give attackers control over the MDM infrastructure and, by extension, visibility into or control of managed mobile devices across an organization.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>Ivanti</category><category>Endpoint Manager Mobile (EPMM)</category></item><item><title>CVE-2026-1340 — Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-1340</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-1340</guid><description>Ivanti Endpoint Manager Mobile (EPMM) contains a code injection flaw that allows unauthenticated attackers to execute arbitrary code remotely — no credentials required. EPMM is a mobile device management platform, meaning a successful exploit could give attackers control over a system that itself manages and has visibility into an organization&apos;s entire mobile device fleet. This makes the blast radius significant, potentially exposing corporate data, configurations, and enrolled devices across the environment.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate><category>Ivanti</category><category>Endpoint Manager Mobile (EPMM)</category></item><item><title>CVE-2026-1603 — Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-1603</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-1603</guid><description>This flaw in Ivanti Endpoint Manager allows a remote attacker with no credentials to bypass authentication via an alternate path or channel and extract stored credential data from the system. Because EPM manages endpoints across an organization, exposed credentials could give attackers a foothold to move laterally or compromise managed devices at scale. No evidence of ransomware exploitation is currently recorded, but credential leakage from an endpoint management platform represents serious organizational risk.</description><pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate><category>Ivanti</category><category> Endpoint Manager (EPM)</category></item><item><title>CVE-2026-1281 — Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-1281</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-1281</guid><description>This vulnerability in Ivanti Endpoint Manager Mobile (EPMM) allows attackers to inject and execute arbitrary code without any authentication. Because EPMM is a mobile device management platform, it typically holds privileged access to corporate devices and sensitive configuration data. A successful exploit could give an attacker full remote control over the server and, by extension, visibility into or control over managed endpoints — making this a high-priority risk for any organization running this product.</description><pubDate>Thu, 29 Jan 2026 00:00:00 GMT</pubDate><category>Ivanti</category><category>Endpoint Manager Mobile (EPMM)</category></item><item><title>CVE-2025-4427 — Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-4427</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-4427</guid><description>Ivanti EPMM exposes an API component that can be accessed without valid credentials due to a flawed implementation of the Spring Framework library. Attackers can craft specific API requests to bypass authentication entirely, reaching protected resources as if they were legitimate administrators. Because EPMM manages mobile devices across an organization, unauthorized access could expose device configurations, credentials, and sensitive enterprise data — making this a high-priority issue for any organization running the product.</description><pubDate>Mon, 19 May 2025 00:00:00 GMT</pubDate><category>Ivanti</category><category>Endpoint Manager Mobile (EPMM)</category></item><item><title>CVE-2025-4428 — Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-4428</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-4428</guid><description>This vulnerability allows an authenticated attacker to remotely execute arbitrary code on Ivanti EPMM systems by sending specially crafted API requests. The flaw stems from an insecure implementation of the Hibernate Validator library. Because EPMM is a mobile device management platform, a successful exploit could give attackers control over the system that manages and enforces security policies across an organization&apos;s entire mobile device fleet — a high-value target with broad organizational access.</description><pubDate>Mon, 19 May 2025 00:00:00 GMT</pubDate><category>Ivanti</category><category>Endpoint Manager Mobile (EPMM)</category></item></channel></rss>