CVE-2026-10727
published 2026-06-09CVE-2026-10727: An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute…
PriorityP263high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
13.63%
96.4th percentile
An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability class is OS command injection (CWE-78) in Ivanti EPMM; monitor for unexpected child processes spawned by the EPMM application server running as root, which may indicate successful exploitation ↗
- →Exploitation requires remote authentication; audit and alert on authenticated API/web requests to Ivanti EPMM endpoints that contain shell metacharacters or command-injection payloads (e.g., ;, |, &&, $(), backticks) in parameter values ↗
- ·Vulnerable versions are Ivanti EPMM before 12.9.0.1, 12.8.0.3, and 12.7.0.2; ensure detection and patching scope covers all three supported release branches ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ivanti
Ivanti Security Advisory: CVE-2026-10727
vendor_ivanti·2026-06-09·CVSS 7.2
CVE-2026-10727 [HIGH] CWE-78 Ivanti Security Advisory: CVE-2026-10727
Ivanti Security Advisory: CVE-2026-10727
An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root
CVE IDs: CVE-2026-10727
CVSS Base Score: 7.2
Severity: HIGH
CWEs: CWE-78
GHSA
An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root
ghsa_unreviewed·2026-06-09
CVE-2026-10727 [HIGH] CWE-78 An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root
An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-09
Published