Ivanti had four vulnerabilities confirmed exploited over the past year across Sentry, Endpoint Manager Mobile (EPMM), and Endpoint Manager (EPM) — including a perfect CVSS 10.0 finding and, notably, the same code-injection root cause appearing twice in EPMM within a two-month span.
CVE-2026-10520, CVSS 10.0, is OS command injection in Ivanti Sentry. CVE-2026-1340 and CVE-2026-1281, both CVSS 9.8, are both code injection in Endpoint Manager Mobile, both explicitly described as allowing unauthenticated remote code execution — disclosed roughly two months apart. CVE-2026-1603, CVSS 8.6, is an authentication bypass in Endpoint Manager that leaks stored credentials.
Why the same bug appearing twice in EPMM is the most important detail here
CVE-2026-1281 and CVE-2026-1340 are described in nearly identical terms — code injection in Endpoint Manager Mobile, unauthenticated remote code execution — and were confirmed exploited about two months apart. That repetition is a stronger signal than either finding alone: it suggests the initial fix for the January finding either didn't fully close the underlying code-injection class in EPMM, or a structurally similar flaw existed elsewhere in the same codebase and was found independently shortly after. Either explanation points to the same practical conclusion — an organization that patched CVE-2026-1281 promptly and considered EPMM secured had, within about two months, a second unauthenticated RCE path to close in the same product.
Why mobile device management platforms carry outsized consequence
Endpoint Manager Mobile exists to manage and enforce policy on an organization's fleet of mobile devices — smartphones and tablets carrying corporate email, credentials, and often access to broader internal systems through mobile-specific applications. An unauthenticated remote code execution vulnerability in the platform managing that fleet is a compromise of the trust relationship the entire mobile fleet depends on, similar in structure to the RMM and patch-management risks discussed elsewhere in this series, but specific to the mobile endpoint category.
What to check this week
Patch EPMM against both CVE-2026-1281 and CVE-2026-1340 explicitly, confirming both fixes are actually applied rather than assuming a single update cycle addressed the underlying issue completely, given how closely related the two findings appear to be.
Treat Ivanti Sentry's CVE-2026-10520 with maximum urgency given its perfect severity score and unauthenticated command-injection mechanism — Sentry's role brokering access between mobile devices and backend resources makes a compromise here a potential bridge into systems well beyond the mobile fleet itself.
Rotate credentials exposed through CVE-2026-1603's authentication bypass as a matter of course, treating any Endpoint Manager instance affected by this CVE the same way a confirmed credential-disclosure incident would be handled elsewhere.
Why Ivanti's history makes this cluster less surprising than it might seem
Ivanti's endpoint and mobile management products have carried a notable history of confirmed-exploited vulnerabilities across recent years, a pattern well documented across the security research community independent of this specific four-CVE cluster. That history is worth factoring into how much scrutiny an organization applies to its Ivanti deployment specifically — a vendor with a demonstrated pattern of recurring critical findings warrants a shorter patch-validation cycle and more frequent advisory review than a vendor without that history, purely as a matter of applied risk management rather than any judgment about the vendor's engineering practices.
A closing note on mobile-specific incident response
Because EPMM sits specifically in the mobile device path, an incident-response plan should confirm it has a mobile-specific playbook — remote wipe, credential rotation across mobile-accessed systems, and device re-enrollment — distinct from the standard desktop and server incident procedures most organizations default to.
A final consideration on procurement decisions
For organizations currently evaluating mobile device management platforms, a vendor's documented history of confirmed-exploited vulnerabilities is a legitimate, quantifiable input into that decision — not the only factor, but one worth weighing alongside feature comparison and cost, given how directly a management platform's own security failures translate into fleet-wide risk.
How Safeguard helps
Safeguard's continuous inventory tracks a vendor's recurring vulnerability patterns within a single product over time, surfacing exactly the kind of two-month repeat finding in EPMM that a one-time patch review might otherwise treat as a closed chapter after the first fix — visibility that matters most precisely when the same underlying weakness resurfaces in a slightly different form shortly after the first was addressed.