Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-6973

Published 2026-05-07
Updated 3 months ago
Vendor/s
Ivanti
Product/s
Endpoint Manager Mobile (EPMM)
Version/s
* > 12.6.1.1
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
7.2
/ 10
High
Severity Details
Base score
7.2 High
Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

Ivanti EPMM CVE-2026-6973 is a high-severity RCE vulnerability under active exploitation. Learn how to patch and secure your MDM environment.

CPE

Ivanti logo
Ivanti
Product Version Start Version End (excl.) Status
endpoint_manager_mobile * 12.6.1.1 vulnerable
endpoint_manager_mobile 12.7.0.0 12.7.0.0 vulnerable
endpoint_manager_mobile 12.8.0.0 12.8.0.0 vulnerable

Related weakness (CWE)

CWE-20

Remediation plan

1

Apply official patches

Immediately install the security updates provided by Ivanti for EPMM. Refer to the May 2026 Security Advisory for detailed installation instructions and to ensure all underlying components are correctly patched against input validation flaws.

2

Update affected systems

Ensure your Ivanti EPMM instances are upgraded to version 12.6.1.1, 12.7.0.1, 12.8.0.1, or later. Systems running versions prior to 12.6.1.1, or specific builds in the 12.7 and 12.8 branches, remain vulnerable to this RCE exploit.

3

Restrict access

Limit access to the Ivanti EPMM administrative console to trusted internal networks only. Implement strict IP whitelisting and ensure that administrative interfaces are not exposed to the public internet to reduce the attack surface for remote exploitation.

4

Monitor for exploitation

Audit administrative logs for unusual activity, specifically looking for unexpected command executions or modifications to system configurations. Monitor network traffic for outbound connections from the EPMM server that may indicate a successful shell or data exfiltration.

Detection Guidance

Organizations should monitor Ivanti EPMM logs for suspicious administrative actions or improper input patterns in web requests. Look for unusual process spawning from the web server user, such as cmd.exe or /bin/sh. Since this is a network-based attack, inspect ingress traffic for payloads targeting administrative endpoints. Review CISA KEV guidance and Ivanti's advisory for specific indicators of compromise associated with known active exploitation campaigns.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management