Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026091401094848 | Publication Time | 2026-09-14 13:22:48 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-14 13:22:48 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Ivanti Endpoint Manager Mobile (EPMM) Contains a Critical Cybersecurity Vulnerability (CVE-2026-18851) |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000011 Ivanti Endpoint Manager Mobile (EPMM) is a mobile device management solution that provides centralized management of iOS, Android, macOS, and Windows devices. Recently, Ivanti issued an advisory regarding a critical cybersecurity vulnerability (CVE-2026-18851, CVSS: 8.8). This is a Missing Authorization vulnerability that allows an authenticated remote attacker to elevate their privileges to administrator. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
Ivanti Endpoint Manager Mobile version 12.9.0.1 and earlier |
|||
|
[Recommended Actions] Please update to the following versions: Ivanti Endpoint Manager Mobile version 12.10.0.0 or later |
|||
|
[Reference] |
|||