← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 8, 2026 · 15:42via Cyber Security News

Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacks

Brief

Ivanti has disclosed a wave of security advisories affecting three flagship enterprise products, Endpoint Manager Mobile , Neurons for ITSM, and Sentry, exposing organizations to risks ranging from privilege escalation to full remote code execution.

The disclosures, published on September 8, 2026, cover ten distinct CVEs, several rated critical, underscoring the breadth of exposure across Ivanti’s mobile device management and IT service management ecosystem.

Ivanti EPMM Vulnerabilities

The first advisory addresses CVE-2026-18851, a high-severity missing authorization flaw in Ivanti Endpoint Manager Mobile (EPMM) carrying a CVSS score of 8.8.

The vulnerability, rooted in CWE-862, allows a remote authenticated attacker to escalate privileges to full administrator access. Versions 12.

  • 0. 1 and earlier, 12.
  • 0. 3 and earlier, and all builds prior to 12.
  • 0. 0 are affected.
Read more on Cyber Security News