Ivanti released fixes for a newly disclosed high-severity flaw in its on-premises Endpoint Manager Mobile (EPMM) platform, tracked as CVE-2026-6973, after confirming limited zero-day exploitation. The vulnerability is caused by improper input validation and can lead to arbitrary code execution when a remote attacker already has administrator-level access. Ivanti said the issue affects EPMM 12.8.0.0 and earlier and issued patched versions 12.6.1.1, 12.7.0.1, and 12.8.0.1, while urging customers to review privileged accounts and rotate credentials. The disclosure adds to a longer pattern of Ivanti security incidents: CISA previously warned that CVE-2023-35082, a critical authentication bypass flaw in Ivanti EPMM and MobileIron Core, was being actively exploited to gain unauthenticated API access, expose user data, and potentially backdoor servers when chained with other vulnerabilities.
ConnectWise also disclosed a critical vulnerability in ConnectWise Automate, tracked as CVE-2026-9089, affecting versions prior to 2026.5. The flaw, classified as CWE-494, stems from insufficient integrity verification during plugin loading and self-update operations and could allow malicious code execution on client machines during agent updates under specific network conditions. ConnectWise assigned the issue a CVSS score of 8.8, automatically updated cloud deployments, and instructed on-premises customers to manually upgrade to version 2026.5; Canada’s Cyber Centre separately urged administrators to apply the vendor update. The disclosures highlight continued risk across widely deployed enterprise management platforms, with internet exposure data showing hundreds of Ivanti EPMM systems and broad operational dependence on remote monitoring and mobile device management software.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Alongside CVE-2026-6973, Ivanti disclosed four more high-severity vulnerabilities affecting EPMM. Ivanti said it had not observed active exploitation of those additional flaws.
Ivanti released security updates for CVE-2026-6973, a high-severity improper input validation flaw in on-premises EPMM that had seen limited zero-day exploitation. The company issued patched versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 and advised customers to review privileged accounts and rotate credentials.
Canada's Cyber Centre published advisory AV26-496 urging administrators to review ConnectWise's security information and apply the ConnectWise Automate 2026.5 update. The notice highlighted that versions prior to 2026.5 are affected.
The CVE-2026-9089 record was published with a description, CWE-494 classification, CVSS details, and a vendor reference. The entry identified ConnectWise Automate 2026.5 as the remediation.
On May 21, 2026, ConnectWise disclosed CVE-2026-9089, a critical flaw in ConnectWise Automate involving insufficient integrity verification during plugin loading and self-update operations. The company said the issue affects versions prior to 2026.5, automatically updated cloud deployments, and required on-premises customers to upgrade manually.
ConnectWise published a security bulletin for ConnectWise Automate 2026.4 on April 20, 2026. This is an earlier, separate vendor security update from the later 2026.5 bulletin tied to CVE-2026-9089.
CISA said CVE-2023-35082 was under active exploitation and added it to the Known Exploited Vulnerabilities Catalog. The agency ordered U.S. federal civilian agencies to remediate affected systems by February 2, 2024 under Binding Operational Directive 22-01.
Ivanti released fixes for CVE-2023-35082 in August 2023. The vulnerability could also help attackers backdoor compromised servers when chained with other flaws.
Rapid7 discovered and reported CVE-2023-35082, a critical authentication bypass vulnerability affecting Ivanti Endpoint Manager Mobile and MobileIron Core. The flaw allows unauthenticated remote API access and exposure of mobile users' personally identifiable information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecysecurity.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourceconnectwise.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.