Ivanti warns of a new vulnerability affecting Endpoint Manager Mobile (EPMM) and has already been exploited in limited attacks.

CVE -2026-6973 (CVSS score: 7.2), is an “improper input validation” issue affecting EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1. It allows a remote authenticated user, with administrator, to achieve remote code execution.
“We are aware of a very limited number of customers affected by the CVE-2026-6973 exploit. Successful exploitation requires Administrator credentials. If customers followed Ivanti's recommendation in January to renew their credentials (due to the CVE-2026-1281 and CVE-2026-1340 exploits), then the risk from CVE-2026-6973 is significantly reduced.“.
See also: Ollama vulnerability allows sensitive information to be leaked
At present, it is not known who is behind the exploitation attempts, whether any of these attacks were successful, and what the ultimate goals of the attacks were.
However, the U.S. Cybersecurity and Infrastructure Security Administration (CISA) added the vulnerability to its list of Known Exploitable Vulnerabilities (KEV), requiring Federal Agencies (FCEBs) to implement the fixes by May 10, 2026.
This case highlights once again how critical security is in mobile device management solutions, especially when they are used in corporate environments with access to sensitive data. While Ivanti has already implemented fixes and mitigations, the fact that the vulnerability has been identified in real attacks shows that organizations cannot rely solely on updates, but also need to continuously monitor and strengthen access mechanisms.
See also: Gemini CLI: Critical vulnerability allowed supply chain attacks

Ivanti EPMM: Multiple Vulnerability Patches
Ivanti has also fixed the following vulnerabilities in EPMM:
– CVE-2026-5786 (CVSS score: 8.8): An improper access control, which allows a remote authenticated attacker to gain administrator access.
– CVE-2026-5787 (CVSS score: 8.9): An improper certificate validation, which allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.
– CVE-2026-5788 (CVSS score: 7.0): An improper access control, which allows a remote unauthenticated attacker to call arbitrary methods.
– CVE-2026-7821 (CVSS score: 7.4): An improper certificate validation vulnerability, which allows a remote unauthenticated attacker to enroll a device, belonging to a limited set of unenrolled devices, leading to disclosure of information about the EPMM device and affecting the integrity of the identity of the newly enrolled device.
See also: Serious vulnerabilities in Salesforce Marketing Cloud

“The issues only affect the on-prem EPMM product endpoint management solution Ivanti’s cloud-based, Ivanti EPM (a similarly named, but different product), Ivanti Sentry, or any other Ivanti product,” the company said.
