logo

Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials

ID: 93045149-2829-5813-8ffb-b79527e243ee

STIX ID: report--93045149-2829-5813-8ffb-b79527e243ee

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Ddos

...
...

Ivanti published an urgent advisory for Endpoint Manager Mobile disclosing five high-severity vulnerabilities — notably CVE-2026-6973 (reported in limited in-the-wild exploitation) and CVE-2026-7821 (an unauthenticated issue relevant to Apple Device Enrollment configurations). Ivanti urges immediate rotation of administrative credentials where applicable and updating to fixed releases 12.6.1.1, 12.7.0.1, or 12.8.0.1 to remediate the issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.