đ° Full Story
Ivanti has disclosed and patched five high-severity vulnerabilities in its on-premises Endpoint Manager Mobile (EPMM) product, including a zero-day, CVE-2026-6973, that was being exploited in limited attacks at the time of disclosure (May 7â8, 2026). The flaw, caused by improper input validation, allows remote code execution by an authenticated user with administrative privileges.
Ivanti released fixes in versions 12.6.1.1, 12.7.0.1 and 12.8.0.1 and advised customers to upgrade, rotate admin credentials and review Sentry and EPMM configurations.
U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-6973 to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to remediate by May 10, 2026.
Ivanti said exploitation was âvery limitedâ and that risk is lower for customers who followed prior January guidance after earlier EPMM zero-days (CVE-2026-1281 and CVE-2026-1340). The disclosure also covers four other high-severity defects, some enabling privilege escalation or unauthenticated certificate manipulation.
Ivanti stressed these issues affect only on-premises EPMM, not its cloud Neurons for MDM or other Ivanti products, and urged immediate patching and network hardening to prevent supply-chain and enterprise mobile management compromises.







đŹ Commentary