Skip to content
Beveiligingsnieuws

Ivanti Endpoint Manager Mobile: actief misbruik CVE’s

actief misbruik Ivanti EPMM

The National Cyber Security Centre (NCSC) issued an alert after it identified serious vulnerabilities in Ivanti Endpoint Manager Mobile (also known as MobileIron). One of these security issues, CVE-2026-6973, is being exploited actively, and the overall risk is assessed as high.

Because attackers may be able to execute code remotely with administrator privileges, organizations that use this software should treat the alert as urgent and focus on deploying the available security updates without delay.

What is Ivanti Endpoint Manager Mobile?

Ivanti Endpoint Manager Mobile is software used by organizations to help manage and secure employee mobile devices within their networks. This typically includes smartphones and tablets, where device management is tied to organizational policies and access to corporate resources.

In short: it sits at the center of mobile device control, which is exactly why vulnerabilities in this component can have serious downstream impact.

Why the NCSC considers the risk high

The NCSC assesses both the likelihood of misuse and potential damage as high. A key reason is that an attacker could be able to perform remote code execution with administrator rights in the most critical case.

The alert also notes that a Proof-of-Concept (PoC) is expected to appear soon. When PoCs become available, the barrier for attackers often drops, increasing the chance of large-scale exploitation.

Which vulnerabilities are in scope?

The alert describes one actively exploited vulnerability and several others that have been addressed with security fixes.

CVE-2026-6973 (actively exploited)

This vulnerability is flagged as the most critical. According to the alert, a malicious actor with administrator rights can execute their own code remotely while leveraging administrator privileges. Importantly, active exploitation has already been observed in a very limited number of customers.

Other fixed vulnerabilities

In addition to CVE-2026-6973, four other vulnerabilities are mentioned as resolved through security updates:

  • CVE-2026-5786: An attacker with valid login credentials could gain remote administrative access.
  • CVE-2026-5787: An attacker could impersonate a trusted system and obtain fraudulent certificates.
  • CVE-2026-5788: An attacker could execute remote code.
  • CVE-2026-7821: An attacker could register devices and gain access to sensitive data.

Together, these issues expand the possible attack paths: from gaining control over management capabilities to intercepting or accessing sensitive information.

How attackers could misuse Ivanti Endpoint Manager Mobile

The NCSC alert outlines several scenarios that map to common enterprise exploitation goals: gaining control, escalating privileges, and extracting sensitive data.

For example, the alert indicates that exploitation could allow an attacker to run code remotely with elevated permissions (in the case of CVE-2026-6973), access management functions using valid credentials (CVE-2026-5786), or trick systems to obtain fake certificates (CVE-2026-5787).

Additionally, the possibility of device registration combined with access to sensitive data (CVE-2026-7821) highlights that attackers may target both control and information assets—not only the management layer.

Potential impact if vulnerabilities are not addressed

If organizations do not apply the security updates, attackers could potentially gain control over mobile devices and compromise sensitive information. The alert highlights outcomes such as:

  • Data breaches caused by unauthorized access to confidential data.
  • Loss of confidentiality when information can be stolen or viewed.
  • Disruption of business processes when device management and security controls are altered or disabled.

Because exploitation has already been detected, the overall risk of harm is considered significant.

What you should do now

The most important action is to install the security updates released by Ivanti to remediate the described vulnerabilities.

The NCSC explicitly advises organizations to install the available updates as quickly as possible, ideally as part of a coordinated change and patch process with your IT or security team.

If you are unsure whether you use the software

If you’re not sure whether your organization uses Ivanti Endpoint Manager Mobile or which version is installed, the NCSC recommends contacting your IT service provider. Your provider can help verify deployment details and determine whether the system is in scope.

Get support from your IT service provider

Ask your IT service provider to help you carry out the necessary security measures. This can include confirming version exposure, planning safe rollout steps, and validating that the system is patched correctly.

Planning a responsible patch approach

Even though speed matters, patching should still be handled methodically. Consider the following practical steps your team can coordinate with your provider:

  • Identify scope: confirm whether Ivanti Endpoint Manager Mobile is deployed and which instances are affected.
  • Deploy the updates: follow Ivanti’s guidance for installing the relevant security updates.
  • Verify outcomes: ensure the patch is applied successfully and that mobile management functions remain stable.
  • Monitor for signs of compromise: check for unusual activity related to administrative access, device registration, or other changes in behavior.

While the alert does not provide specific detection indicators, it does make it clear that attackers already have a feasible path—so monitoring and verification are sensible parts of reducing risk.

Why this alert deserves immediate attention

This is not merely a theoretical vulnerability report. The alert states that the most critical issue (CVE-2026-6973) is actively being misused, even if at the moment it is limited to a small number of customers.

At the same time, the expectation of a Proof-of-Concept being released soon suggests that the exploitation landscape could change rapidly. As a result, organizations should prioritize patching now to reduce the window of opportunity for attackers.

Conclusion

The NCSC alert makes one message clear: the vulnerabilities in Ivanti Endpoint Manager Mobile present a high risk, especially because CVE-2026-6973 is actively exploited and may enable remote code execution with administrator privileges.

To protect mobile devices, prevent unauthorized access to sensitive data, and reduce the likelihood of disruption, install the security updates from Ivanti as soon as possible. If you need help determining whether you are affected or how to apply the patches correctly, involve your IT service provider immediately.

Source: https://www.ncsc.nl/alerts/actief-misbruik-ivanti-endpoint-manager-mobile