Ivanti released security patches addressing two high severity Ivanti vulnerabilities in its enterprise mobility management solutions. These flaws affect Ivanti Sentry and Ivanti Endpoint Manager Mobile (EPMM). Both vulnerabilities allow attackers to obtain administrative privileges on targeted appliances.
- Product: Ivanti (2 products)
- Vulnerabilities: 2 flaws (CVE-2026-83527, CVE-2026-18851)
- Highest severity: 8.8 (High · CVSSv3)
- Status: No confirmed exploitation yet; patches available
- Action: Update to R10.8.2, R10.7.3, R10.6.4, 12.10.0.0 (+2) now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-18851 | 8.8 | CWE-862 | 12.10.0.0, 12.9.0.2, 12.8.0.4 | Not exploited |
| CVE-2026-83527 | 8.1 | CWE-288 | R10.8.2, R10.7.3, R10.6.4 | Not exploited |
Why This Matters
Industry estimates show tens of thousands of corporate networks rely on Ivanti solutions for device management. Consequently, compromising these gateways exposes sensitive enterprise data and internal resources. Ivanti Sentry protects application traffic, while EPMM manages client mobile devices. Therefore, unpatched systems risk total administrative compromise by malicious actors.
How the Attack Works
The first flaw, CVE-2026-83527, involves an authentication bypass mechanism within Ivanti Sentry. According to the Ivanti Sentry security advisory, the flaw “allows a remote unauthenticated attacker to gain administrative level access.” Attackers exploit this issue over the network without user interaction.
Meanwhile, the second flaw, CVE-2026-18851, resides in Ivanti EPMM. Furthermore, the vendor confirmed in the Ivanti EPMM security advisory that missing authorization “allows a remote authenticated attacker to escalate their privileges to admin.” Hence, an attacker with low-level privileges can seize complete administrative control.
Affected Versions
For Sentry, CVE-2026-83527 impacts versions R10.8.1, R10.7.2, and R10.6.3 and all prior releases. Moreover, these Ivanti vulnerabilities impact deployments managed by EPMM and Ivanti Neurons for MDM. For EPMM, CVE-2026-18851 affects versions 12.9.0.1, 12.8.0.3, and older builds.
Patch and Mitigation Steps
Fortunately, Ivanti stated, “We are not aware of any customers being exploited by this vulnerability at the time of disclosure.” No public proof-of-concept exploits currently exist. Administrators must patch these Ivanti vulnerabilities immediately. Sentry administrators should install versions R10.8.2, R10.7.3, or R10.6.4. Similarly, EPMM users must update to versions 12.10.0.0, 12.9.0.2, or 12.8.0.4 to secure their networks.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!