Vulnerabilities & PatchesEmerging1 src
Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacks
Ivanti has disclosed a wave of security advisories affecting three flagship enterprise products, Endpoint Manager Mobile , Neurons for ITSM, and Sentry, exposing organizations to risks ranging from privilege escalation to full remote code execution.
The disclosures, published on September 8, 2026, cover ten distinct CVEs, several rated critical, underscoring the breadth of exposure across Ivanti’s mobile device management and IT service management ecosystem.
Ivanti EPMM Vulnerabilities
The first advisory addresses CVE-2026-18851, a high-severity missing authorization flaw in Ivanti Endpoint Manager Mobile (EPMM) carrying a CVSS score of 8.8.
The vulnerability, rooted in CWE-862, allows a remote authenticated attacker to escalate privileges to full administrator access. Versions 12. 9. 0. 1 and earlier, 12. 8. 0. 3 and earlier, and all builds prior to 12. 10. 0. 0 are affected.