Critical Vulnerabilities in Ivanti EPMM Expose Systems to Remote Attacks
Article Content
- •CVE-2026-5787 allows impersonation of Sentry hosts to obtain valid certificates.
- •CVE-2026-5788 enables remote attackers to invoke arbitrary methods.
- •Both vulnerabilities affect Ivanti EPMM versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1.
Two critical vulnerabilities (CVE-2026-5787 and CVE-2026-5788) were disclosed in Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1. CVE-2026-5787 allows attackers to impersonate Sentry hosts and obtain valid CA-signed client certificates, while CVE-2026-5788 enables unauthorized method invocation. Both vulnerabilities can be exploited by remote unauthenticated attackers, posing significant risks to affected systems. The vulnerabilities were published on May 7, 2026, and are currently unpatched. Organizations using vulnerable versions of Ivanti EPMM are advised to take immediate action to mitigate potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-5787 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…