Ivanti Products can run code

Published September 10, 2026

Ivanti's mobile device management, cloud automation, and traffic security tools have flaws that let attackers run their own code on your systems. If an attacker succeeds, they could install programs, change or delete files, or run malicious code or network.

Severity
Not scoredNo CVSS score recorded
Fix
Fix not establishedNo fixed release identified in this report
Affects
Ivanti
Exploited
Not confirmedNo confirmation recorded

How it works

  • Attackers can send specially crafted requests to Ivanti Endpoint Manager Mobile, Ivanti Neurons, or Ivanti Sentry.
  • These requests trick the software into running code that the attacker controls.
  • If the attacker's code runs with high privileges, they can install programs, change or delete files, or run malicious code or network.
  • The flaws exist in how the software handles certain inputs, allowing attackers to bypass security checks and execute their own commands.

What to do

Check your installed version of Ivanti Endpoint Manager Mobile, Ivanti Neurons, or Ivanti Sentry. If you are running an affected version, you are exposed. Ivanti has not specified exact version cutoffs, so check the vendor's advisory for the full affected range and prerequisites. You can find your version by checking the software's About or version screen or by consulting your deployment logs.

Update to the latest patched version of Ivanti Endpoint Manager Mobile, Ivanti Neurons, or Ivanti Sentry. Ivanti has not specified an exact fixed version in the advisory, so check the vendor's advisory for the latest patch instructions. After updating, verify the new version number matches the patched release. If you cannot update immediately, disable the affected features or isolate the systems from untrusted networks until you can apply the patch.

Technical details

Ivanti EPMM (Endpoint Manager Mobile), Ivanti Neurons, and Ivanti Sentry contain multiple vulnerabilities, the most critical of which allows arbitrary code execution. An attacker exploiting this flaw could run malicious code on the affected system with the same privileges as the logged-in user, enabling program installation, data modification, deletion, or other actions based on the user's permissions. The vulnerabilities affect Ivanti EPMM, Ivanti Neurons, and Ivanti Sentry, with no specific patched versions listed in the source. The issue was reported under CVE identifier NEWS-e0a4df1f057a3dddf5.