Ivanti EPMM and Sentry RCE flaws patched
Ivanti patched multiple vulnerabilities in EPMM and Sentry products allowing remote code execution and security policy bypass.
The French CERT has issued an advisory regarding multiple vulnerabilities discovered in Ivanti Endpoint Manager Mobile (EPMM) and Ivanti Sentry products. The vulnerabilities enable attackers to achieve remote arbitrary code execution and bypass security policies.
Affected products include EPMM versions 12.8.x prior to 12.8.0.3, 12.9.x prior to 12.9.0.1, and versions earlier than 12.7.0.2. Sentry versions 10.6.x prior to 10.6.2, 10.7.x prior to 10.7.1, and versions earlier than 10.5.2 are also vulnerable. Four CVEs have been assigned to these vulnerabilities: CVE-2026-6973 and CVE-2026-10727 affecting EPMM, and CVE-2026-10520 and CVE-2026-10523 affecting Sentry.
Ivanti released security updates on June 9, 2026, addressing all identified vulnerabilities. Organizations using affected versions should apply the vendor-provided patches immediately to mitigate the risk of remote code execution attacks.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0724
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free