← Vulnerability feed

Vulnerability record · CVE-2026-7821 · published 7 May 2026

CVE-2026-7821: Ivanti endpoint manager mobile improper certificate validation vulnerability

Ivanti · Endpoint Manager Mobile

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.

9.1 CVSS 3.1 Critical EPSS 0.87% · top 43.0% CWE-295 · Improper certificate validation
9.1CVSS 3.1 base score
0.87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-7821 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-1281Ivanti Endpoint Manager Mobile unauthenticated code injection RCEIvanti Endpoint Manager Mobile (EPMM) contains a code injection flaw (CWE-94) that permits unauthenticated remote code execution. With a CVSS 3.1 bas…KEVEPSS 99%analysed9.8CVE-2026-1340Ivanti Endpoint Manager Mobile code injection enables unauthenticated RCEIvanti Endpoint Manager Mobile (EPMM) contains a code injection flaw (CWE-94) that allows attackers to achieve unauthenticated remote code execution.…KEVEPSS 99%analysed9.8CVE-2023-35082Ivanti EPMM authentication bypass via unauthenticated API accessIvanti Endpoint Manager Mobile (EPMM) 11.10 and older contains an authentication bypass that lets unauthenticated users reach restricted functionalit…KEVEPSS 100%analysed9.8CVE-2023-35078Ivanti EPMM authentication bypass via unauthenticated API accessIvanti Endpoint Manager Mobile (EPMM) contains an improper authentication flaw (CWE-287) that lets unauthenticated users reach restricted functionali…KEVEPSS 100%analysed8.8CVE-2025-4428Ivanti Endpoint Manager Mobile API code injection enables remote code executionIvanti Endpoint Manager Mobile (EPMM) 12.5.0.0 and prior contains a code injection flaw in its API component that lets an authenticated attacker exec…KEVEPSS 87%analysed7.5CVE-2025-4427Ivanti Endpoint Manager Mobile API authentication bypassIvanti Endpoint Manager Mobile 12.5.0.0 and earlier contains an authentication bypass in its API component, allowing access to protected resources wi…KEVEPSS 100%analysed7.2CVE-2026-6973Ivanti EPMM improper input validation enables remote code executionIvanti Endpoint Manager Mobile (EPMM) before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 contains an improper input validation flaw (CWE-20) that lets …KEVEPSS 2.5%analysed7.2CVE-2023-35081Ivanti EPMM path traversal allows authenticated admin arbitrary file writeIvanti Endpoint Manager Mobile (EPMM) contains a path traversal flaw (CWE-22) in versions 11.10.x before 11.10.0.3, 11.9.x before 11.9.1.2, and 11.8.…KEVEPSS 64%analysed

Source: NIST National Vulnerability Database (record CVE-2026-7821), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.