Ivanti Warns of Exploited EPMM Flaw CVE-2026-6973
The vulnerability (CVE-2026-6973) exists in Ivanti Endpoint Manager Mobile (EPMM) is being exploited by threat actors.

The vulnerability (CVE-2026-6973) exists in Ivanti Endpoint Manager Mobile (EPMM) is being exploited by threat actors.
May 8, 2026 | 2 min read

Ivanti is warning customers to issue fixes for a vulnerability in its mobile device management platform, which has been exploited in attacks.
The vulnerability (CVE-2026-6973) exists in Ivanti Endpoint Manager Mobile (EPMM), used by organizations to manage and secure employee mobile devices. Ivanti did not give further details about the exploitation activity for the flaw except for saying that a “very limited number” of customers have been impacted by attacks, and stressing that successful exploitation requires administrative authentication.
“An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution,” according to Ivanti on Thursday.
Ivanti has patched the flaw in versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 of EPMM.
The company said that there are not currently any reliable IoCs that can be used to tell if customers have been compromised. The company recommends customers review accounts with Admin rights, and rotate those credentials. The “most conservative approach” would be for all customers to review and rotate all admin credentials, according to Ivanti.
“If customers followed Ivanti’s recommendation in January to rotate credentials if you were exploited with CVE-2026-1281 and CVE-2026-1340, then your risk of exploitation from CVE-2026-6973 is significantly reduced,” according to Ivanti. CVE-2026-1281 is a critical Ivanti remote code execution flaw, while CVE-2026-1340 is an EPMM unauthenticated remote code injection flaw.
In its advisory, Ivanti also disclosed four other flaws. These are:
Ivanti said it was not aware of any customers being exploited via CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, or CVE-2026-7821 at the time the vulnerabilities were publicly disclosed. According to the company, the flaws were discovered internally.
May 8, 2026 | 2 min read
Lindsey O’Donnell-Welch is an award-winning journalist who strives to shed light on how security issues impact not only businesses and defenders on the front line, but also the daily lives of consumers.