Ivanti is warning customers to issue fixes for a vulnerability in its mobile device management platform, which has been exploited in attacks.

The vulnerability (CVE-2026-6973) exists in Ivanti Endpoint Manager Mobile (EPMM), used by organizations to manage and secure employee mobile devices. Ivanti did not give further details about the exploitation activity for the flaw except for saying that a “very limited number” of customers have been impacted by attacks, and stressing that successful exploitation requires administrative authentication.

“An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution,” according to Ivanti on Thursday

Ivanti has patched the flaw in versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 of EPMM.

The company said that there are not currently any reliable IoCs that can be used to tell if customers have been compromised. The company recommends customers review accounts with Admin rights, and rotate those credentials. The “most conservative approach” would be for all customers to review and rotate all admin credentials, according to Ivanti.

“If customers followed Ivanti’s recommendation in January to rotate credentials if you were exploited with CVE-2026-1281 and CVE-2026-1340, then your risk of exploitation from CVE-2026-6973 is significantly reduced,” according to Ivanti. CVE-2026-1281 is a critical Ivanti remote code execution flaw, while CVE-2026-1340 is an EPMM unauthenticated remote code injection flaw.

In its advisory, Ivanti also disclosed four other flaws. These are: 

  • CVE-2026-5786: A high-severity, improper access control flaw in Ivanti EPMM enabling remote authenticated attackers to gain administrative access
  • CVE-2026-5787: An improper certificate validation bug in Ivanti EPMM enabling remote unauthenticated attackers to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.
  • CVE-2026-5788: An improper access control vulnerability in Ivanti EPMM allowing a remote unauthenticated attacker to invoke arbitrary methods.
  • CVE-2026-7821: An improper certificate validation in Ivanti EPMM allowing a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about the EPMM appliance and possibly impacting on the integrity of the newly enrolled device identity.

Ivanti said it was not aware of any customers being exploited via CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, or CVE-2026-7821 at the time the vulnerabilities were publicly disclosed. According to the company, the flaws were discovered internally.