Skip to content
VulniPulse

Ivanti EPMM / MobileIron Vulnerabilities & Security Advisories

6 advisories tracked · Ivanti Security Advisories · 1 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Ivanti advisory that VulniPulse classified as EPMM / MobileIron, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 6 high.

Android app · Google Play

Monitor Ivanti CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Ivanti Security Advisories

Polled via Ivanti's official Security Advisory blog RSS. Posts summarize each monthly/out-of-band advisory and link to the canonical Ivanti Security Advisory KB. Ivanti Connect Secure, Policy Secure and EPMM are frequent, high-priority exploitation targets.

Latest Ivanti EPMM / MobileIron advisories

HighIvanti Exploited

High June 2026 Security Update

Ivanti releases standard security patches on the second Tuesday of every month. In today’s rapidly evolving technology and threat landscape, we believe responsible transparency should be a cornerstone of any product security program. AI is compressing the time-to-exploit, and Ivanti uses leading technologies to proactively find and fix issues ––including integrating advanced LLMs into our Engineering and product security to enhance the capabilities of our teams. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) and Ivanti Sentry. It is important for customers to know: We have no evidence of these vulnerabilities being exploited in the wild. These vulnerabilities do not impact any other Ivanti solutions.

EPMM / MobileIronEndpoint ManagerSentry
Jun 9, 2026
HighIvanti Exploited CISA KEV

High [CVE-2026-6973] May 2026 EPMM Security Update

In today’s rapidly evolving technology and threat landscape, responsible transparency should be a cornerstone of any product security program. Especially with the advancements in AI, we believe it is important to respond quickly when a new risk is discovered. Ivanti’s efforts integrating AI into our development and product security process have increased the capabilities of our Engineering and Product Security Red Teams to identify and fix vulnerabilities. Our objective in proactively discovering issues is to increase the resilience of our products in today’s threat environment and reduce the likelihood of exploited-in-the-wild Zero Days. We have already successfully identified vulnerabilities traditional tools missed, including some that are being disclosed today. Importantly, we are committed to using AI responsibly in product security, including keeping a human in the loop to verify automated or agentic work. Our top priority is the security of our customers, and we expect that this work will naturally increase the number of vulnerabilities found, fixed, and disclosed. While this will result in an uptick in disclosures, we see this as a good thing, and an important part of ensuring our products keep pace with modern security requirements as they change. Affected products named by the advisory: Neurons; EPMM; Endpoint Manager; Sentry.

CVE-2026-6973
EPMM / MobileIronNeuronsEndpoint ManagerSentry
May 7, 2026
HighIvanti

High January 2026 EPMM Security Update

At Ivanti, responsible transparency is a cornerstone of our commitment to customer security and trust. We have a long-standing commitment to provide information that allows our customers and the broader security ecosystem to take proactive measures to safeguard their environments, while mitigating the risks of a rapidly evolving and highly sophisticated threat landscape. To this end, we are issuing an important security update addressing vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM). More information can be found in the Security Advisory. At the time of disclosure, we are aware of a very limited number of customers whose solution has been exploited. The issue affects only the on-prem EPMM product. It is not present in Ivanti Neurons for MDM, Ivanti’s cloud-based unified endpoint management solution, Ivanti EPM (a similarly named, but different product), Ivanti Sentry, or any other Ivanti products. We urge all customers using the on-prem EPMM product to promptly install the Security Update. As we respond to this situation, we are making the following information available to defenders now: Our Security Advisory, which describes the nature of the vulnerabilities and detailed remediation instructions for customers. A Technical Analysis that includes affected endpoint specifics and log analysis guidance to support investigation and forensics.

EPMM / MobileIronNeuronsEndpoint ManagerSentry
Jan 29, 2026
HighIvanti Exploited

High October 2025 Security Update

Ivanti releases standard security patches on the second Tuesday of every month. Our vulnerability management program is central to our commitment to maintaining secure products. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. We believe that responsible transparency helps protect our customers, and that CVE disclosures are an essential and effective tool to communicate software vulnerabilities. The purpose of assigning a CVE is to provide a beacon to security teams and signal the need for urgent updates. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) and Neurons for MDM. It is important for customers to know: We have no evidence of any of these vulnerabilities being exploited in the wild. These vulnerabilities do not impact any other Ivanti solutions. Our Support team is always available to help customers and partners should they have any questions. Cases can be logged via the Success portal (login credentials required).

EPMM / MobileIronNeuronsEndpoint Manager
Oct 14, 2025
HighIvanti Exploited

High July Security Update

Ivanti releases standard security patches on the second Tuesday of every month. Our vulnerability management program is central to our commitment to maintaining secure products. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. We believe that responsible transparency helps protect our customers, and that CVE disclosures are an essential and effective tool to communicate software vulnerabilities. The purpose of assigning a CVE is to provide a beacon to security teams and signal the need for urgent updates. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Connect Secure and Policy Secure, Ivanti EPM, and Ivanti EPMM. It is important for customers to know: We have no evidence of any of these vulnerabilities being exploited in the wild. These vulnerabilities do not impact any other Ivanti solutions. Cases can be logged via the Success portal (login credentials required). Want to stay up to date on Ivanti Security Advisories?

Connect Secure (VPN)Policy SecureEPMM / MobileIronEndpoint Manager
Jul 8, 2025
HighIvanti

High EPMM Security Update

At Ivanti, transparency is a cornerstone of our commitment to customer security and trust. It is through such transparency that vulnerabilities are swiftly addressed, allowing our customers and the broader ecosystem to take proactive measures to safeguard their environments amidst a rapidly evolving and highly sophisticated threat landscape. To this end, we are issuing an important security update addressing vulnerabilities associated with open-source libraries used in Ivanti Endpoint Manager Mobile (EPMM). We have provided an FAQ below and in the Security Advisory. At the time of disclosure, we are aware of a very limited number of customers whose solution has been exploited. The issue only affects the on-prem EPMM product. It is not present in Ivanti Neurons for MDM, Ivanti’s cloud-based unified endpoint management solution, Ivanti Sentry, or any other Ivanti products. We urge all customers using the on-prem EPMM product to promptly install the patch. We have made additional resources and support teams available to assist customers in implementing the patch and addressing any concerns. Detailed information is available in our Security Advisory so that customers can protect their environment. Thank you to our customers and security partners for their engagement and support, which enabled our swift response to this issue.

EPMM / MobileIronNeuronsEndpoint ManagerSentry
May 13, 2025

← All Ivanti advisories