logo

U.S. CISA adds a flaw in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalog

ID: d69f971a-8cd1-569d-ba1c-72a8a73eb365

STIX ID: report--d69f971a-8cd1-569d-ba1c-72a8a73eb365

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Pierluigi Paganini

...
...

CISA added CVE-2026-6973 — a high-severity (CVSS 7.1) arbitrary code execution flaw in Ivanti Endpoint Manager Mobile (EPMM) that requires admin authentication — to its Known Exploited Vulnerabilities catalog; Ivanti has released patches for affected versions and federal agencies are ordered to remediate by May 10, 2026 due to limited in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.