logo

Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access

ID: c83eab69-6fac-557b-9a64-a7878c895c65

STIX ID: report--c83eab69-6fac-557b-9a64-a7878c895c65

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: [email protected] (The Hacker News)

...
...

Ivanti disclosed and patched multiple high-severity vulnerabilities in its on-prem Endpoint Manager Mobile (EPMM) product — most notably CVE-2026-6973 (CVSS 7.2), which can yield remote code execution for a remotely authenticated admin and has been observed in limited attacks. CISA added CVE-2026-6973 to its Known Exploited Vulnerabilities catalog requiring federal agencies to remediate by May 10, 2026; Ivanti also fixed four related vulnerabilities (CVE-2026-5786/5787/5788/7821) impacting access control and certificate validation. The issues affect only the on-prem EPMM product, not Ivanti’s cloud offerings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.