Known vulnerabilities in Endpoint Manager Mobile (formerly MobileIron Core)

Vendor: Ivanti
Software CPE: cpe:2.3:a:ivanti:mobileiron_core:*:*:*:*:*:*:*:*
Total vulnerabilities: 34
Public exploits: 9
Known exploited (KEV): 10
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Endpoint Manager Mobile (formerly MobileIron Core) Endpoint Manager Mobile (formerly MobileIron Core) is affected by 34 known vulnerabilities: 5 critical, 10 high, 7 medium, 12 low Critical High Medium Low

Vulnerabilities (34)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU134235 - Configuration
CWE-16 Low
No
No
12.7.0.2, 12.8.0.3, 12.9.0.1 10.06.2026 SB2026061072
#VU134233 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-10727
CWE-78 Low
No
No
12.7.0.2, 12.8.0.3, 12.9.0.1 10.06.2026 SB2026061072
#VU130635 - Improper Access Control
CVE-2026-5786
CWE-284 Medium
No
No
12.6.1.1, 12.7.0.1, 12.8.0.1 07.05.2026 SB20260507244
#VU130636 - Improper Certificate Validation
CVE-2026-5787
CWE-295 High
No
No
12.6.1.1, 12.7.0.1, 12.8.0.1 07.05.2026 SB20260507244
#VU130637 - Improper Access Control
CVE-2026-5788
CWE-284 Medium
No
No
12.6.1.1, 12.7.0.1, 12.8.0.1 07.05.2026 SB20260507244
#VU130638 - Improper input validation
CVE-2026-6973
CWE-20 High
No
Exploited
12.6.1.1, 12.7.0.1, 12.8.0.1 07.05.2026 SB20260507244
#VU130639 - Improper Certificate Validation
CVE-2026-7821
CWE-295 Medium
No
No
12.6.1.1, 12.7.0.1, 12.8.0.1 07.05.2026 SB20260507244
#VU122131 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-1340
CWE-94 Critical
Available
Exploited
- 29.01.2026 SB2026012972
#VU122130 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-1281
CWE-94 Critical
Available
Exploited
- 29.01.2026 SB2026012972
#VU117115 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-10986
CWE-22 Low
No
No
12.4.0.4, 12.5.0.4, 12.6.0.2 14.10.2025 SB2025101498
#VU117113 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-10243
CWE-78 Low
No
No
12.4.0.4, 12.5.0.4, 12.6.0.2 14.10.2025 SB2025101498
#VU117114 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-10985
CWE-78 Low
No
No
12.4.0.4, 12.5.0.4, 12.6.0.2 14.10.2025 SB2025101498
#VU117112 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-10242
CWE-78 Low
No
No
12.4.0.4, 12.5.0.4, 12.6.0.2 14.10.2025 SB2025101498
#VU112529 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-6771
CWE-78 Low
No
No
12.3.0.3, 12.4.0.3, 12.5.0.2 08.07.2025 SB2025070870
#VU112528 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-6770
CWE-78 Low
No
No
12.3.0.3, 12.4.0.3, 12.5.0.2 08.07.2025 SB2025070870
#VU109170 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-4428
CWE-94 High
Available
Exploited
11.12.0.5, 12.3.0.2, 12.4.0.2, 12.5.0.1 14.05.2025 SB2025051355
SB2025112459
#VU109035 - Authentication Bypass Using an Alternate Path or Channel
CVE-2025-4427
CWE-288 Critical
Available
Exploited
11.12.0.5, 12.3.0.2, 12.4.0.2, 12.5.0.1 13.05.2025 SB2025051355
#VU98396 - Incorrect Permission Assignment for Critical Resource
CVE-2024-7612
CWE-732 Low
No
No
12.0, 12.0.0.5, 12.1.0.4 11.10.2024 SB2024101120
#VU94519 - Improper Authentication
CVE-2024-34788
CWE-287 Medium
No
No
11.12.0.3, 12.0.0.3, 12.1.0.1 18.07.2024 SB2024071823
#VU94518 - Improper Authentication
CVE-2024-36132
CWE-287 High
No
No
11.12.0.3, 12.0.0.3, 12.1.0.1 18.07.2024 SB2024071823


Showing elements 1 - 20 out of 34