References https://avd.aliyun.com/detail?id=AVD-2026-5786 https://cve.imfht.com/detail/CVE-2026-5786 https://www.twcert.org.tw/tw/cp-169-10903-17476-1.html https://thehackernews.com/2026/05/ivanti-epmm-cve-2026-6973-rce-under.html https://ccb.belgium.be/advisories/warning-authenticated-remote-code-execution-vulnerability-ivanti-epmm-exploited-patch https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs
Related VulnerabilitiesPoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code Injection旭辰資訊|SmartIT Desktop Manager - 存在4個漏洞中成科信票务管理系统 /SystemManager/TicketSystem/ReturnTicketPlance.ashx SQL 注入漏洞中成科信票务管理系统 /SystemManager/Planetarium/ReserveTicketManagerPlane.ashx SQL 注入漏洞PoCCVE-2020-10204: Sonatype Nexus Repository Manager 3 - Remote Code ExecutionPoCccm-detect: Clear-Com Core Configuration Manager Panel - Detect智慧物联网综合服务平台ListFileManager存在目录枚举漏洞WP User Manager /profile/admin/about 文件包含漏洞(CVE-2026-9290)SteVe /steve/manager/signin 默认口令漏洞PoCCVE-2008-2052: Bitrix Site Manager 6.5 - Open RedirectPoCCVE-2026-10520: Ivanti Sentry - OS Command InjectionPoCCVE-2026-9290: WP User Manager – User Profile Builder & Membership - Local File InclusionWP User Manager /profile/admin/about 本地文件包含漏洞