Posting Date: 2026/09/17

【Vulnerability Alert】Ivanti's Endpoint Manager Mobile (EPMM) Contains a Critical Security Vulnerability (CVE-2026-18851)

  • Subject:【Vulnerability Alert】Ivanti's Endpoint Manager Mobile (EPMM) Contains a Critical Security Vulnerability (CVE-2026-18851)


  • Description:
    • Forwarded from TWCERT/CC Security Advisory TWCERTCC-200-202609-00000011
    • Ivanti Endpoint Manager Mobile (EPMM) is a mobile device management solution that centrally manages iOS, Android, macOS and Windows devices. Ivanti recently issued a critical security vulnerability advisory (CVE-2026-18851, CVSS: 8.8). This is a missing authorization vulnerability, allowing authenticated remote attackers to escalate their privileges to administrator.
  • Affected Platforms:
    • Ivanti Endpoint Manager Mobile versions up to and including 12.9.0.1
    • Ivanti Endpoint Manager Mobile versions up to and including 12.8.0.3
  • Recommended Actions:
    • Please update to the following versions: Ivanti Endpoint Manager Mobile 12.10.0.0 and later, Ivanti Endpoint Manager Mobile 12.90.2 and later, Ivanti Endpoint Manager Mobile 12.8.0.4 and later
  • References:

Computer and Communication Center
Network System Division