ctipilot.chSwitzerland · Europe · Public sector

Ivanti EPMM on-prem — pre-auth certificate impersonation (CVSS 9.1, ITW, KEV chain with CVE-2026-6973)

cve · CVE-2026-5787

Story timeline

  1. 2026-05-08CTI Daily Brief — 2026-05-08
    immediate-actionsFirst coverage. CWE-295; unauthenticated attacker impersonates Sentry host registration to obtain valid CA-signed client certificate; chains with CVE-2026-6973 for pre-auth RCE. Fixed in 12.6.1.1/12.7.0.1/12.8.0.1. Deep dive § 7.