
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5787 is an Improper Certificate Validation vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates. It affects Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1 (specifically versions before 12.6.1.1, 12.7.0.0, and 12.8.0.0). The vulnerability was published on May 7, 2026, and patches were released the same day. It carries a CVSS v3.1 base score of 9.1 (Critical) per NVD, and 8.9 (High) per ENISA/GitHub Advisory (GitHub Advisory, Ivanti Advisory).
The root cause is classified as CWE-295 (Improper Certificate Validation), meaning Ivanti EPMM fails to properly validate certificates presented by hosts claiming to be registered Sentry instances. An unauthenticated remote attacker can exploit this flaw over the network by impersonating a legitimate Sentry host during the certificate enrollment process, causing EPMM to issue valid CA-signed client certificates to the attacker-controlled host. No user interaction or prior privileges are required, making this exploitable entirely remotely. The attack is associated with CAPEC-459 (Creating a Rogue Certification Authority Certificate) and CAPEC-475 (Signature Spoofing by Improper Validation) (GitHub Advisory, Ivanti Advisory).
Successful exploitation allows an attacker to obtain CA-signed client certificates that authenticate them as trusted Sentry infrastructure components within the enterprise mobile management environment. This enables the attacker to authenticate as trusted infrastructure, compromising both the confidentiality and integrity of the EPMM deployment — potentially enabling interception of managed device communications, lateral movement within the enterprise, and further attacks against mobile device management (MDM) infrastructure. Availability is not directly impacted, but the trust compromise can have cascading effects on enterprise security posture (GitHub Advisory, Feedly).
CVE-2026-5787 has been reported as exploited in the wild in conjunction with CVE-2026-6973 (an authenticated RCE vulnerability in EPMM), forming a pre-authentication chain that enables full compromise. Reports indicate that credentials stolen in January 2026 attacks were leveraged in zero-day exploitation of related EPMM flaws, and approximately 850 EPMM servers were identified as internet-exposed at the time of disclosure. The vulnerability was added to CISA's Known Exploited Vulnerabilities (KEV) catalog, with a KEV remediation deadline noted as May 10, 2026. The EPSS score is approximately 0.045–0.064%, and no standalone public proof-of-concept exploit has been confirmed for this specific CVE (BleepingComputer, DarkWebInformer, GitHub Advisory).
Ivanti has released patched versions addressing CVE-2026-5787: upgrade to EPMM 12.6.1.1, 12.7.0.1, or 12.8.0.1 or later. If immediate patching is not possible, implement network segmentation to restrict access to EPMM systems and limit exposure of the certificate enrollment endpoint to trusted network segments only. Additionally, review and revoke any suspicious client certificates issued during the vulnerability window, and monitor for unauthorized certificate issuance. Given active exploitation and CISA KEV listing, patching should be treated as urgent (Ivanti Advisory, GitHub Advisory).
Ivanti issued a security advisory on May 7, 2026, disclosing CVE-2026-5787 alongside CVE-2026-6973 and other EPMM flaws, noting active exploitation in targeted attacks. BleepingComputer, The Hacker News, SecurityWeek, CyberScoop, and HelpNetSecurity all covered the disclosure, highlighting the zero-day exploitation and the chaining of CVE-2026-5787 with CVE-2026-6973 for pre-auth to RCE attack chains. Kudelski Security published technical analysis of the related RCE vulnerability. The Belgian Centre for Cybersecurity (CCB) and Ireland's NCSC issued warnings to their constituencies. Community trackers noted approximately 850 internet-exposed EPMM servers, amplifying urgency (BleepingComputer, SecurityWeek, CyberScoop).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."