VORANT. Threat Intelligence Sign in Get the full feed

Ivanti EPMM and Sentry RCE flaws patched

critical vulnerability

Ivanti patched multiple vulnerabilities in EPMM and Sentry products allowing remote code execution and security policy bypass.

The French CERT has issued an advisory regarding multiple vulnerabilities discovered in Ivanti Endpoint Manager Mobile (EPMM) and Ivanti Sentry products. The vulnerabilities enable attackers to achieve remote arbitrary code execution and bypass security policies.

Affected products include EPMM versions 12.8.x prior to 12.8.0.3, 12.9.x prior to 12.9.0.1, and versions earlier than 12.7.0.2. Sentry versions 10.6.x prior to 10.6.2, 10.7.x prior to 10.7.1, and versions earlier than 10.5.2 are also vulnerable. Four CVEs have been assigned to these vulnerabilities: CVE-2026-6973 and CVE-2026-10727 affecting EPMM, and CVE-2026-10520 and CVE-2026-10523 affecting Sentry.

Ivanti released security updates on June 9, 2026, addressing all identified vulnerabilities. Organizations using affected versions should apply the vendor-provided patches immediately to mitigate the risk of remote code execution attacks.

Mentioned in this report

Vulnerabilities CVE-2026-10520KEVCVE-2026-10523CVE-2026-10727CVE-2026-6973KEV

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0724

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free