
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7821 is an improper certificate validation vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about the EPMM appliance and compromising the integrity of the newly enrolled device identity. It affects Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1, including specific versions 12.7.0.0 and 12.8.0.0. The vulnerability was published on May 7, 2026. It carries a CVSS v3.1 base score of 9.1 (Critical) per NVD, though the GitHub Advisory Database and ENISA rate it at 7.4 (High) using a higher attack complexity assumption (GitHub Advisory, Ivanti Advisory).
The root cause is classified as CWE-295 (Improper Certificate Validation), meaning the EPMM appliance fails to properly validate certificates during the device enrollment process. This allows an unauthenticated remote attacker to bypass certificate-based authentication controls and enroll a device that belongs to a restricted set of unenrolled devices — effectively impersonating a legitimate device. The attack vector is network-based, requires no privileges or user interaction, and the scope is unchanged. Related attack patterns include CAPEC-459 (Creating a Rogue Certification Authority Certificate) and CAPEC-475 (Signature Spoofing by Improper Validation). No public proof-of-concept code has been identified for this specific CVE (GitHub Advisory, Ivanti Advisory).
Successful exploitation allows an unauthenticated remote attacker to enroll an unauthorized device into the EPMM system, resulting in high confidentiality impact (disclosure of sensitive EPMM appliance information) and high integrity impact (compromise of the enrolled device's identity). Availability is not directly affected. The ability to enroll rogue devices could enable further lateral movement within a managed device environment, as the attacker's device would be treated as a trusted, enrolled endpoint by the EPMM infrastructure (GitHub Advisory, Ivanti Advisory).
As of the time of disclosure, there is no evidence of a public proof-of-concept exploit specifically for CVE-2026-7821, and no confirmed in-the-wild exploitation of this specific CVE has been reported. The EPSS score is approximately 0.045–0.064%, placing it in a low-to-moderate exploitation probability range. However, CVE-2026-7821 was disclosed alongside CVE-2026-6973 (an actively exploited RCE vulnerability in EPMM), and the broader EPMM vulnerability cluster has attracted significant threat actor attention, with approximately 850 internet-exposed EPMM servers identified (BleepingComputer, GitHub Advisory). CVE-2026-7821 itself does not appear in the CISA KEV catalog based on available data.
Ivanti has released patched versions addressing CVE-2026-7821: 12.6.1.1, 12.7.0.1, and 12.8.0.1. Organizations should upgrade to one of these versions immediately. As interim mitigations, implement network segmentation to restrict access to the EPMM appliance from untrusted or external networks, and monitor device enrollment activities for suspicious patterns indicative of unauthorized enrollment attempts (Ivanti Advisory, GitHub Advisory).
CVE-2026-7821 was disclosed as part of a broader May 2026 Ivanti EPMM security advisory covering multiple CVEs, with significant media attention focused primarily on the co-disclosed CVE-2026-6973 (an actively exploited RCE). Security outlets including BleepingComputer, SecurityWeek, The Hacker News, CyberScoop, and Help Net Security covered the advisory cluster, noting that Ivanti customers were again confronting actively exploited zero-days in EPMM (BleepingComputer, SecurityWeek). Researchers noted that approximately 850 EPMM servers were internet-exposed at the time of disclosure, amplifying concern about the attack surface (Logicity). The Belgian Centre for Cybersecurity and Ireland's NCSC also issued advisories related to the EPMM vulnerability cluster (CCB Belgium).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."