IVANTI has issued security patches for two high‑severity vulnerabilities affecting its Sentry and Endpoint Manager Mobile (EPMM) products. The flaws, CVE-2026-83527 in Sentry and CVE-2026-18851 in EPMM, could allow remote attackers to obtain administrative privileges on targeted appliances. Ivanti reports both issues as not exploited at the time of disclosure, with patches available to mitigate the risk.
CVE-2026-83527 is an authentication bypass in Ivanti Sentry, meaning a remote, unauthenticated attacker could gain administrative‑level access over the network without user interaction. CVE-2026-18851 in EPMM involves missing authorization, enabling a remote attacker with low‑level privileges to escalate to admin and take full control. Affected versions include Sentry R10.8.1, R10.7.2, R10.6.3 and earlier, and EPMM versions 12.9.0[.]1, 12.8.0[.]3 and older builds.
Ivanti has published fixed releases: Sentry should be updated to R10.8.2, R10.7.3 or R10.6.4; EPMM should move to 12.10.0[.]0, 12.9.0[.]2 or 12.8.0[.]4. The company emphasises that the vulnerabilities are severe because compromised gateways could expose sensitive enterprise data and internal resources across networks relying on Ivanti for device management and traffic protection. Administrators are urged to update promptly to secure deployments.