Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access
Ivanti is alerting users to a new security vulnerability affecting Endpoint Manager Mobile (EPMM) that has been investigated in a small number of real-world attacks.
A case of incorrect input validation impacting EPMM prior to versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 is the high-severity vulnerability CVE-2026-6973 (CVSS score: 7.2).
According to an advisory issued today by Ivanti, it enables remote code execution for a remotely authenticated user with administrator access.
A very small number of clients have been exploited with CVE-2026-6973, as far as we are aware. Admin authentication is necessary for exploitation to be successful. Your risk of being exploited by CVE-2026-6973 is much decreased if customers followed Ivanti's advice in January to rotate credentials if you were...

