EUVD-2026-28396
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 7 May 2026. Evidence sources: cisa_kev.
- ENISA score
- 7.2 · CVSS 3.1
- Advisory evidence
- 3 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2026-0135Kwetsbaarheden verholpen in Ivanti Endpoint Manager Mobile
- csaf_ncscnl · NCSC-2026-0190Kwetsbaarheden verholpen in Ivanti Endpoint Manager Mobile
