Back to News
Vulnerabilities

Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access

Cyber RTMay 11, 20263 min read
Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access

Ivanti has identified a high-severity vulnerability, CVE-2026-6973, in Endpoint Manager Mobile (EPMM) that allows remote code execution by authenticated users. This flaw, along with four others, has been exploited in limited attacks. Ivanti advises credential rotation to mitigate risks. The U.S. CISA has listed it in the Known Exploited Vulnerabilities catalog, mandating fixes by May 2026. The issue affects only on-prem EPMM products.

Ivanti has issued a warning about a new security vulnerability impacting its Endpoint Manager Mobile (EPMM) software. This high-severity flaw, identified as CVE-2026-6973, has a CVSS score of 7.2 and stems from improper input validation in EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1. The vulnerability allows a remotely authenticated user with administrative access to execute remote code, posing significant security risks. The company has noted that the exploitation of this vulnerability has been limited to a small number of customers. Successful exploitation requires administrative authentication. Ivanti had previously advised customers to rotate credentials in January if they were affected by earlier vulnerabilities, CVE-2026-1281 and CVE-2026-1340, which can help mitigate the risk associated with CVE-2026-6973. Details about the attackers, the success of the attacks, and their objectives remain unclear. However, the situation has prompted action from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), which has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog. CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies apply the necessary patches by May 10, 2026. In addition to CVE-2026-6973, Ivanti has also addressed four other vulnerabilities in EPMM. These include CVE-2026-5786, an improper access control flaw with a CVSS score of 8.8, which allows remote authenticated attackers to gain administrative access. Another is CVE-2026-5787, a certificate validation issue with a CVSS score of 8.9, enabling attackers to impersonate registered Sentry hosts. Further vulnerabilities include CVE-2026-5788, with a CVSS score of 7.0, which permits remote unauthenticated attackers to invoke arbitrary methods, and CVE-2026-7821, with a CVSS score of 7.4, which involves improper certificate validation allowing unauthorized device enrollment and information disclosure. These vulnerabilities collectively highlight significant security challenges for EPMM users. Ivanti has clarified that these issues are specific to the on-premises EPMM product and do not affect other Ivanti solutions, such as Ivanti Neurons for MDM, Ivanti EPM, Ivanti Sentry, or any other products offered by the company. This distinction is crucial for customers using different Ivanti services to assess their risk exposure accurately. The article concludes by encouraging readers to follow Ivanti on various platforms like Google News, Twitter, and LinkedIn for more exclusive content and updates. This call to action underscores the importance of staying informed about security developments and company advisories to mitigate potential risks effectively.