📦 Endpoint Manager Mobile

by Ivanti

🔍 What is Endpoint Manager Mobile?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-1340

CRITICAL CVSS 9.8 Jan 29, 2026

This critical vulnerability in Ivanti Endpoint Manager Mobile allows unauthenticated attackers to inject malicious code and execute arbitrary commands remotely. All organizations using vulnerable vers...

CVE-2026-1281

CRITICAL CVSS 9.8 Jan 29, 2026

CVE-2026-1281 is a critical code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthenticated attackers to execute arbitrary code remotely. This affects organizations u...

CVE-2024-36130

CRITICAL CVSS 9.8 Aug 7, 2024

This vulnerability allows an unauthorized attacker on the same network to bypass authentication in Ivanti EPMM's web component and execute arbitrary commands on the underlying operating system. It aff...

CVE-2023-39335

CRITICAL CVSS 9.8 Nov 15, 2023

This vulnerability allows unauthenticated attackers to impersonate any existing user during device enrollment in Ivanti EPMM (formerly MobileIron Core). It affects EPMM versions 11.10, 11.9, 11.8 and ...

CVE-2023-35082

CRITICAL CVSS 9.8 Aug 15, 2023

CVE-2023-35082 is an authentication bypass vulnerability in Ivanti EPMM (formerly MobileIron Core) that allows remote unauthenticated attackers to access administrative API endpoints. This affects Iva...

CVE-2023-35078

CRITICAL CVSS 9.8 Jul 25, 2023

CVE-2023-35078 is an authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthenticated attackers to access administrative APIs and functionality. This affects or...

CVE-2025-10242

HIGH CVSS 7.2 Oct 14, 2025

This vulnerability allows authenticated administrators in Ivanti EPMM to execute arbitrary operating system commands through the admin panel, leading to remote code execution. It affects organizations...

CVE-2025-10985

HIGH CVSS 7.2 Oct 14, 2025

This CVE describes an OS command injection vulnerability in Ivanti EPMM admin panel that allows authenticated administrators to execute arbitrary commands on the underlying system. Attackers with admi...

CVE-2025-6771

HIGH CVSS 7.2 Jul 8, 2025

This vulnerability allows authenticated attackers with high privileges in Ivanti Endpoint Manager Mobile (EPMM) to execute arbitrary operating system commands through command injection. Attackers can ...

CVE-2025-6770

HIGH CVSS 7.2 Jul 8, 2025

CVE-2025-6770 is an OS command injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows authenticated attackers with high privileges to execute arbitrary commands on the server. Th...

CVE-2025-4428

HIGH CVSS 7.2 May 13, 2025

This vulnerability allows authenticated attackers to execute arbitrary code on Ivanti Endpoint Manager Mobile (EPMM) systems by sending specially crafted API requests. It affects organizations using I...

CVE-2024-7612

HIGH CVSS 8.8 Oct 8, 2024

This vulnerability allows local authenticated attackers to modify sensitive components in Ivanti EPMM due to insecure permissions. Organizations running Ivanti EPMM versions before 12.1.0.4 are affect...

CVE-2024-36132

HIGH CVSS 7.5 Aug 7, 2024

This authentication bypass vulnerability in Ivanti EPMM allows remote attackers to access sensitive resources without proper credentials. It affects Ivanti Endpoint Manager for Mobile (EPMM) versions ...

CVE-2025-4427

MEDIUM CVSS 5.3 May 13, 2025

An authentication bypass vulnerability in Ivanti Endpoint Manager Mobile's API allows attackers to access protected resources without valid credentials. This affects organizations using Ivanti EPMM ve...

CVE-2023-46807

MEDIUM CVSS 6.7 May 22, 2024

An SQL injection vulnerability in Ivanti EPMM's web component allows authenticated users with appropriate privileges to access or modify database data. This affects EPMM versions before 12.1.0.0. Atta...