CVE-2026-7821: Critical severity Ivanti EPMM vulnerability
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti EPMMto a version that resolves this vulnerability.Fixed in 12.6.1.1 - Upgrade
Upgrade
Ivanti EPMMto a version that resolves this vulnerability.Fixed in 12.7.0.1 - Upgrade
Upgrade
Ivanti EPMMto a version that resolves this vulnerability.Fixed in 12.8.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7821?
CVE-2026-7821 is considered a critical vulnerability due to the potential for remote unauthenticated exploitation.
How do I fix CVE-2026-7821?
To resolve CVE-2026-7821, upgrade your Ivanti EPMM to version 12.6.1.1, 12.7.0.1, or 12.8.0.1 or later.
What impact does CVE-2026-7821 have on my system?
CVE-2026-7821 can lead to unauthorized device enrollment and potential information disclosure about the EPMM appliance.
Who is vulnerable to CVE-2026-7821?
Organizations using Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1 are vulnerable to CVE-2026-7821.
Can CVE-2026-7821 be exploited remotely?
Yes, CVE-2026-7821 can be exploited remotely by an unauthenticated attacker.