NEW: BlackBerry UEM 12.20 patch released CVE-2026-3821 affects Microsoft Intune deployments Samsung Knox 3.12 update addresses critical MDM flaws Android 15 enterprise enrollment changes now live NEW: BlackBerry UEM 12.20 patch released CVE-2026-3821 affects Microsoft Intune deployments Samsung Knox 3.12 update addresses critical MDM flaws Android 15 enterprise enrollment changes now live
BES / UEM

BlackBerry Enterprise Server & UEM: The Complete 2026 Guide

BlackBerry's transition from BES 12 to the Unified Endpoint Management platform reshaped enterprise mobile security architecture across thousands of regulated-industry deployments.

This guide covers BES-to-UEM migration paths, current UEM deployment topologies, policy configuration for regulated industries, and the security hardening steps IT administrators need in 2026.

In-depth read 12 min read
BlackBerry Enterprise Server and UEM platform diagram

Latest Coverage

All articles →
Patch

June 2026 Enterprise Mobile Security Patches

A consolidated roundup of June 2026 patches across BlackBerry UEM, Google Android Enterprise, and Samsung Knox — severity ratings and recommended deployment timelines.

MDM Security

BYOD Security Policy Guide for Enterprise IT Teams

How to build and enforce a BYOD security policy that balances employee privacy with enterprise data protection — covering MDM enrollment tiers, acceptable-use rules, and audit requirements.

Vulnerabilities

Major Mobile Endpoint Security Breaches of 2026

A documented timeline of significant enterprise mobile endpoint breaches in 2026 — covering attack vectors, the MDM or EMM platforms involved, lateral movement techniques, and post-incident containment actions taken.

Stay ahead of the next mobile breach

Weekly digest of enterprise mobile security alerts, BlackBerry BES/UEM updates, MDM platform vulnerabilities and hardware intelligence — delivered to security professionals.

No advertising. Security signal only.

Browse by Coverage Area

BES / UEM

Migration guides, deployment topologies, policy configuration, and security hardening for BlackBerry Enterprise Server and UEM.

Vulnerabilities

CVE tracker, breach timelines, and in-depth analysis of critical vulnerabilities across enterprise MDM and EMM platforms.

MDM Security

Zero trust, BYOD policy, per-app VPN, conditional access, and security architecture guidance for enterprise device management.

QNX Security

Automotive cybersecurity, ISO 21434 compliance, microkernel isolation, and threat analysis for BlackBerry QNX-powered systems.

Enterprise Mobile Security: Frequently Asked Questions

What is BlackBerry UEM and how does it differ from BES 12?

BlackBerry UEM (Unified Endpoint Manager) is the current enterprise mobility management platform from BlackBerry, released in 2017 as a successor to BES 12. Unlike BES 12, which required separate server roles for iOS and Android management, UEM manages iOS, Android, Windows, and macOS devices from a single console. BES 12 reached end-of-support on December 31, 2020 and no longer receives security patches — migration to UEM is a security-critical remediation for any organization still running BES 12 infrastructure.

How often are enterprise mobile security patches released?

Patch cadences vary by platform. Apple releases iOS security patches approximately every 4 to 6 weeks, with Rapid Security Responses (RSRs) available for actively exploited zero-days on shorter timelines. Google publishes the Android Security Bulletin on the first Monday of each month. BlackBerry releases UEM updates quarterly for major versions and as-needed for critical CVEs. Enterprise IT teams should maintain a minimum security patch level compliance policy in their MDM platform and monitor CISA's Known Exploited Vulnerabilities catalog for priority guidance.

What is MDM and what enterprise platforms are most widely deployed?

Mobile Device Management (MDM) software enables IT teams to remotely manage, configure, and secure mobile devices. The most widely deployed enterprise MDM platforms in 2026 are Microsoft Intune (dominant in Microsoft 365 environments), BlackBerry UEM (regulated industries and security-focused deployments), VMware Workspace ONE (enterprise-scale, Broadcom-acquired), and JAMF Pro (macOS and iOS focused). The MDM platform choice significantly affects the security controls available for policy enforcement, compliance monitoring, and remote wipe capability.

What is BlackBerry QNX used for in 2026?

BlackBerry QNX is a real-time operating system (RTOS) used in safety-critical and embedded computing applications. In 2026, QNX powers over 235 million vehicles as the foundational OS for automotive infotainment systems, ADAS compute platforms, digital instrument clusters, and connected telematics control units. Beyond automotive, QNX is deployed in industrial control systems, medical devices, and defense electronics where both functional safety (ISO 26262 ASIL D) and cybersecurity (ISO 21434) are required simultaneously.

What enterprise mobile security vulnerabilities should IT teams prioritize in 2026?

The highest-priority enterprise mobile security vulnerabilities in 2026 are in web rendering engines (WebKit on iOS, Blink on Android) — consistently exploited in zero-day attacks. MDM platform vulnerabilities represent a second critical category: a compromised MDM server gives an attacker control over all managed devices simultaneously. Bluetooth stack vulnerabilities affecting proximity-based attacks have also increased in 2026. CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative prioritization source for enterprise security teams.

What is zero-trust mobile security?

Zero-trust mobile security applies the zero-trust principle — never trust, always verify — to enterprise mobile device access. Rather than granting broad network access based on device enrollment status alone, zero-trust mobile architectures use continuous authentication, device posture checks (OS version, patch level, compliance status), app-level encryption, and micro-segmented access via per-app VPN or SASE solutions. BlackBerry UEM implements zero-trust through BlackBerry Dynamics app-level containerization and policy-driven conditional access that evaluates device health before each resource access request.