Ivanti EPMM Zero-Day RCE Exploited, Federal Agencies Urged to Patch
Patch Ivanti Endpoint Manager Mobile to version 12.6.1.1 or later to fix CVE‑2026‑6973.
Patch Ivanti Endpoint Manager Mobile to version 12.6.1.1 or later to fix CVE‑2026‑6973.
Summary
On May 7, Ivanti announced that a high‑severity remote code execution flaw, CVE‑2026‑6973, in its Endpoint Manager Mobile (EPMM) 12.8.0.0 and earlier releases had already been exploited in zero‑day attacks. The vulnerability, caused by improper input validation, allows attackers who possess administrative credentials to run arbitrary code on the affected system. Ivanti released patch versions 12.6.1.1, 12.7.0.1 and 12.8.0.1 to fix the issue and urged customers to review and rotate administrative passwords. The advisory noted that exploitation requires admin authentication and that only a limited number of attacks have been observed to date.
The flaw is part of a broader set of high‑severity vulnerabilities that Ivanti addressed in the same advisory, including CVE‑2026‑5786, 5787, 5788 and 7821, which could also grant administrative access or enable impersonation of Sentry hosts. Shadowserver reports that more than 850 EPMM appliances are exposed online, with the majority located in Europe and North America. CISA has added CVE‑2026‑6973 to its list of actively exploited vulnerabilities and issued a four‑day directive for federal agencies to patch the flaw. The deadline, set for midnight Sunday, May 10, follows a similar earlier mandate for CVE‑2026‑1340, underscoring the urgency of addressing the vulnerability.
Federal agencies and other organizations using EPMM are now under pressure to apply the patches promptly. Ivanti clarified that the flaw does not affect its cloud products, such as Neurons for MDM, and that the risk is confined to on‑premises installations. The incident highlights the ongoing threat of zero‑day exploits in widely deployed endpoint management software and the importance of rapid patching, credential hygiene, and continuous monitoring of exposed assets.
Key changes
- CVE‑2026‑6973 is an improper input validation flaw in Ivanti Endpoint Manager Mobile.
- Affects all EPMM releases before 12.6.1.1, 12.7.0.1, and 12.8.0.1.
- Allows remotely authenticated admin users to execute arbitrary code.
- CVSS score 7.2 indicates high severity.
- Ivanti released a patch addressing the input validation issue.
- Failure to patch could compromise mobile endpoints and grant full administrative control.