PT-2026-38457 · Ivanti · Epmm

Published

2026-05-07

·

Updated

2026-06-12

·

CVE-2026-7821

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ivanti EPMM versions prior to 12.6.1.1 Ivanti EPMM versions prior to 12.7.0.1 Ivanti EPMM versions prior to 12.8.0.1
Description Improper certificate validation allows a remote unauthenticated attacker to enroll a device from a restricted set of unenrolled devices. This leads to information disclosure regarding the EPMM appliance and compromises the integrity of the newly enrolled device identity.
Recommendations Update to version 12.6.1.1 or later. Update to version 12.7.0.1 or later. Update to version 12.8.0.1 or later.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7821

Affected Products

Epmm