Ivanti EPMM CVE-2026-6973 is a high-severity RCE vulnerability under active exploitation. Learn how to patch and secure your MDM environment.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| endpoint_manager_mobile | * | 12.6.1.1 | vulnerable |
| endpoint_manager_mobile | 12.7.0.0 | 12.7.0.0 | vulnerable |
| endpoint_manager_mobile | 12.8.0.0 | 12.8.0.0 | vulnerable |
Immediately install the security updates provided by Ivanti for EPMM. Refer to the May 2026 Security Advisory for detailed installation instructions and to ensure all underlying components are correctly patched against input validation flaws.
Ensure your Ivanti EPMM instances are upgraded to version 12.6.1.1, 12.7.0.1, 12.8.0.1, or later. Systems running versions prior to 12.6.1.1, or specific builds in the 12.7 and 12.8 branches, remain vulnerable to this RCE exploit.
Limit access to the Ivanti EPMM administrative console to trusted internal networks only. Implement strict IP whitelisting and ensure that administrative interfaces are not exposed to the public internet to reduce the attack surface for remote exploitation.
Audit administrative logs for unusual activity, specifically looking for unexpected command executions or modifications to system configurations. Monitor network traffic for outbound connections from the EPMM server that may indicate a successful shell or data exfiltration.
Organizations should monitor Ivanti EPMM logs for suspicious administrative actions or improper input patterns in web requests. Look for unusual process spawning from the web server user, such as cmd.exe or /bin/sh. Since this is a network-based attack, inspect ingress traffic for payloads targeting administrative endpoints. Review CISA KEV guidance and Ivanti's advisory for specific indicators of compromise associated with known active exploitation campaigns.
Experience superior visibility and a simpler approach to cyber risk management