logo

Ivanti EPMM vulnerability exploited in zero-day attacks (CVE-2026-6973)

ID: f66b74cb-00fc-5b79-9635-36b6b78e2f58

STIX ID: report--f66b74cb-00fc-5b79-9635-36b6b78e2f58

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Zeljka Zorz

...
...

Ivanti released patches for five high-severity vulnerabilities in Endpoint Manager Mobile (EPMM), including CVE-2026-6973 — a zero-day that allows remote code execution with administrative privileges and has been exploited in a limited number of customers; Ivanti recommends upgrading to fixed versions and rotating admin credentials, and CISA has added the vulnerability to its Known Exploited Vulnerabilities list.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.