cbcvebase.
CVE-2026-10727
published 2026-06-09

CVE-2026-10727: An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute…

PriorityP263high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
13.63%
96.4th percentile
An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root

Detection & IOCsextracted from sources · hover to see the quote

  • →Vulnerability class is OS command injection (CWE-78) in Ivanti EPMM; monitor for unexpected child processes spawned by the EPMM application server running as root, which may indicate successful exploitation ↗
  • →Exploitation requires remote authentication; audit and alert on authenticated API/web requests to Ivanti EPMM endpoints that contain shell metacharacters or command-injection payloads (e.g., ;, |, &&, $(), backticks) in parameter values ↗
  • ·Vulnerable versions are Ivanti EPMM before 12.9.0.1, 12.8.0.3, and 12.7.0.2; ensure detection and patching scope covers all three supported release branches ↗
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.