High severity7.2NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026
CVE-2026-10727
CVE-2026-10727
Description
An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root
Affected products
1- Range: <12.9.0.1, <12.8.0.3, <12.7.0.2
Patches
Vulnerability mechanics
References
1News mentions
1- Critical Vulnerabilities Patched in Fortinet, Ivanti ProductsSecurityWeek · Jun 10, 2026