NCSC-2026-0359 [1.00] [M/H] Kwetsbaarheid verholpen in Ivanti Endpoint Manager Mobile
Ivanti heeft een kwetsbaarheid verholpen in Ivanti Endpoint Manager Mobile. De kwetsbaarheid betreft een ontbrekende autorisatiecontrole in Ivanti Endpoint Manager Mobile versies ouder dan 12.10.0.0, 12.9.0.2 en 12.8.0.4. Hierdoor kunnen geauthenticeerde gebruikers hun privileges verhogen tot een administratief niveau.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0359
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-188511.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18851 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEU] [hoch] Ivanti Endpoint Manager Mobile: Schwachstelle ermöglicht Erlangen von Administratorrechtencert-bund
- unknownMultiples vulnérabilités dans les produits Ivanti (09 septembre 2026)cert-fr-avis
- unknownIvanti security advisory (AV26-897)cccs
- highCVE-2026-18851: Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, an…nvd
Recent advisories for Kwetsbaarheid verholpen in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0357 [1.00] [M/H] Kwetsbaarheid verholpen in Ivanti Sentryncsc-nl · 2026-09-09
- unknownexploitedNCSC-2026-0354 [1.00] [M/H] Kwetsbaarheid verholpen in Google Chromencsc-nl · 2026-09-09
- unknownexploitedNCSC-2026-0344 [1.00] [H/H] Kwetsbaarheid verholpen in Adobe Commerce en Magentoncsc-nl · 2026-09-08
- unknownexploitedNCSC-2026-0342 [1.00] [H/H] Kwetsbaarheid verholpen in N-central van N-ablencsc-nl · 2026-09-07
- unknownexploitedNCSC-2026-0336 [1.00] [M/H] Kwetsbaarheid verholpen in JFrog Artifactoryncsc-nl · 2026-09-02
- unknownexploitedNCSC-2026-0324 [1.00] [M/H] Kwetsbaarheid verholpen in Zimbra Collaboration Suitencsc-nl · 2026-08-23
More from NCSC-NL Advisories
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustrator2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager2026-09-09
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion2026-09-09
- unknownNCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commerce2026-09-09