Ivanti warns of new EPMM flaw exploited in zero-day attacks
ID: cac6f762-a188-5d6b-8178-76225cfac4e8
STIX ID: report--cac6f762-a188-5d6b-8178-76225cfac4e8
Feed Name: Bleeping Computer
Ivanti patched a high-severity remote code execution zero-day (CVE-2026-6973) in Endpoint Manager Mobile (EPMM) that has seen very limited exploitation; customers are advised to install patched builds (12.6.1.1, 12.7.0.1, 12.8.0.1), review and rotate admin credentials, and note that Shadowserver is tracking ~850 exposed EPMM IPs online. The advisory also covers four additional high-severity EPMM flaws (CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, CVE-2026-7821) and references prior exploited EPMM zero-days and CISA guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
