logo

Ivanti EPMM CVE-2026-6973 Allows RCE with Admin Credentials, Under Active Exploitation

ID: 88d36e01-5a5d-5c9f-8427-89d1a7a2851a

STIX ID: report--88d36e01-5a5d-5c9f-8427-89d1a7a2851a

Feed Name: Kudelski Security

Threat Score
78/100

Date Published: 2026-05-07

Date Updated: 2026-07-22

...
...

CVE-2026-6973 is a high-severity RCE vulnerability in Ivanti Endpoint Manager Mobile (EPMM) affecting versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1; Ivanti reports limited active exploitation that requires valid administrative credentials. Ivanti released patches (and four additional high-severity EPMM fixes) and CISA issued an emergency directive requiring federal agencies to patch by 10 May 2026; recommended mitigations include immediate patching, administrative credential rotation, and log review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.