Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access
ID: c83eab69-6fac-557b-9a64-a7878c895c65
STIX ID: report--c83eab69-6fac-557b-9a64-a7878c895c65
Feed Name: The Hacker News
Ivanti disclosed and patched multiple high-severity vulnerabilities in its on-prem Endpoint Manager Mobile (EPMM) product — most notably CVE-2026-6973 (CVSS 7.2), which can yield remote code execution for a remotely authenticated admin and has been observed in limited attacks. CISA added CVE-2026-6973 to its Known Exploited Vulnerabilities catalog requiring federal agencies to remediate by May 10, 2026; Ivanti also fixed four related vulnerabilities (CVE-2026-5786/5787/5788/7821) impacting access control and certificate validation. The issues affect only the on-prem EPMM product, not Ivanti’s cloud offerings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
