Briefing

Ivanti EPMM Zero-Day RCE Exploited, Federal Agencies Urged to Patch

security
by [email protected] (The Hacker News) · CVE-2026-6973

Patch Ivanti Endpoint Manager Mobile to version 12.6.1.1 or later to fix CVE‑2026‑6973.

What to do now

Patch Ivanti Endpoint Manager Mobile to version 12.6.1.1 or later to fix CVE‑2026‑6973.

Summary

On May 7, Ivanti announced that a high‑severity remote code execution flaw, CVE‑2026‑6973, in its Endpoint Manager Mobile (EPMM) 12.8.0.0 and earlier releases had already been exploited in zero‑day attacks. The vulnerability, caused by improper input validation, allows attackers who possess administrative credentials to run arbitrary code on the affected system. Ivanti released patch versions 12.6.1.1, 12.7.0.1 and 12.8.0.1 to fix the issue and urged customers to review and rotate administrative passwords. The advisory noted that exploitation requires admin authentication and that only a limited number of attacks have been observed to date.

The flaw is part of a broader set of high‑severity vulnerabilities that Ivanti addressed in the same advisory, including CVE‑2026‑5786, 5787, 5788 and 7821, which could also grant administrative access or enable impersonation of Sentry hosts. Shadowserver reports that more than 850 EPMM appliances are exposed online, with the majority located in Europe and North America. CISA has added CVE‑2026‑6973 to its list of actively exploited vulnerabilities and issued a four‑day directive for federal agencies to patch the flaw. The deadline, set for midnight Sunday, May 10, follows a similar earlier mandate for CVE‑2026‑1340, underscoring the urgency of addressing the vulnerability.

Federal agencies and other organizations using EPMM are now under pressure to apply the patches promptly. Ivanti clarified that the flaw does not affect its cloud products, such as Neurons for MDM, and that the risk is confined to on‑premises installations. The incident highlights the ongoing threat of zero‑day exploits in widely deployed endpoint management software and the importance of rapid patching, credential hygiene, and continuous monitoring of exposed assets.

Key changes

  • CVE‑2026‑6973 is an improper input validation flaw in Ivanti Endpoint Manager Mobile.
  • Affects all EPMM releases before 12.6.1.1, 12.7.0.1, and 12.8.0.1.
  • Allows remotely authenticated admin users to execute arbitrary code.
  • CVSS score 7.2 indicates high severity.
  • Ivanti released a patch addressing the input validation issue.
  • Failure to patch could compromise mobile endpoints and grant full administrative control.

Affects

enterprise internal

Source angles · 3 perspectives

The Hacker News
Independent angle

Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access

Open
Bleeping Computer
Independent angle

Ivanti warns of new EPMM flaw exploited in zero-day attacks

Open
Bleeping Computer
Independent angle

CISA gives feds four days to patch Ivanti flaw exploited as zero‑day

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting