logo

Ivanti Endpoint Manager Mobile Vulnerability Enables Remote Code Execution Attacks

ID: 851ab8a8-e38f-51d0-9de5-daa79355d0d9

STIX ID: report--851ab8a8-e38f-51d0-9de5-daa79355d0d9

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Abinaya

...
...

A high-severity configuration-injection vulnerability (CVE-2026-6973) in Ivanti Endpoint Manager Mobile (EPMM) allows authenticated, high-privilege attackers to inject arbitrary Apache directives and achieve remote code execution; affected versions include 12.9.0, 12.8.0.2, and 12.7.0.1, and Ivanti has released patches (12.9.0.1, 12.8.0.3, 12.7.0.2). Immediate patching, review of privileged access controls, and monitoring for unusual Apache behavior are recommended, although Ivanti reports no evidence of active exploitation or public IOCs at disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.