Posting Date: 2026/09/17
【Vulnerability Alert】Ivanti's Endpoint Manager Mobile (EPMM) Contains a Critical Security Vulnerability (CVE-2026-18851)
- Subject:【Vulnerability Alert】Ivanti's Endpoint Manager Mobile (EPMM) Contains a Critical Security Vulnerability (CVE-2026-18851)
- Description:
- Forwarded from TWCERT/CC Security Advisory TWCERTCC-200-202609-00000011
- Ivanti Endpoint Manager Mobile (EPMM) is a mobile device management solution that centrally manages iOS, Android, macOS and Windows devices. Ivanti recently issued a critical security vulnerability advisory (CVE-2026-18851, CVSS: 8.8). This is a missing authorization vulnerability, allowing authenticated remote attackers to escalate their privileges to administrator.
- Affected Platforms:
- Ivanti Endpoint Manager Mobile versions up to and including 12.9.0.1
- Ivanti Endpoint Manager Mobile versions up to and including 12.8.0.3
- Recommended Actions:
- Please update to the following versions: Ivanti Endpoint Manager Mobile 12.10.0.0 and later, Ivanti Endpoint Manager Mobile 12.90.2 and later, Ivanti Endpoint Manager Mobile 12.8.0.4 and later
- References:
Computer and Communication Center
Network System Division