Ivanti disclosed active exploitation of CVE-2026-6973, a high-severity improper input validation flaw in on-premises Endpoint Manager Mobile (EPMM) that allows remote code execution when used with administrator authentication. The company said exploitation has been limited to a small number of customers and assessed with high confidence that attackers are using administrator credentials stolen during earlier January attacks involving CVE-2026-1281 and CVE-2026-1340. Affected versions are EPMM releases prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1; Ivanti said Neurons for MDM, EPM, Sentry, and other products are not affected.
Ivanti also patched four additional high-severity EPMM flaws—CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, and CVE-2026-7821—covering certificate validation and access-control weaknesses that could enable host impersonation, unauthorized access, arbitrary method invocation, and unauthorized device enrollment, though the vendor said it has no evidence those bugs were exploited. CISA added CVE-2026-6973 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to remediate by May 10, 2026, while national cyber agencies in Canada and Finland urged immediate patching. Ivanti advised customers to rotate EPMM administrator credentials, review privileged accounts, hunt for compromise artifacts such as webshells and reverse shells, and reduce public exposure of management interfaces; internet scans have identified more than 850 exposed EPMM instances, mainly in Europe and North America.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On May 7, 2026, CISA added Ivanti EPMM flaw CVE-2026-6973 to its Known Exploited Vulnerabilities catalog after reports of active exploitation. Under Binding Operational Directive 22-01, federal agencies were ordered to remediate the issue by May 10, 2026.
On May 7, 2026, Ivanti assessed with high confidence that attackers exploiting CVE-2026-6973 were using administrator credentials stolen during the January attacks on CVE-2026-1281 and CVE-2026-1340. The company advised customers to rotate EPMM admin credentials, review privileged accounts, and check for compromise artifacts.
On May 7, 2026, Ivanti published a security advisory for five EPMM vulnerabilities, including actively exploited RCE flaw CVE-2026-6973, and released fixed versions 12.6.1.1, 12.7.0.1, and 12.8.0.1. Ivanti said exploitation was limited, required administrator authentication, and affected only on-premises EPMM, not other Ivanti products.
In April 2026, CISA directed U.S. federal civilian agencies to secure affected Ivanti EPMM systems within four days following the earlier January zero-day activity. This marked formal U.S. government response to the prior EPMM exploitation.
In January 2026, Ivanti disclosed and responded to exploitation of EPMM vulnerabilities CVE-2026-1281 and CVE-2026-1340. Ivanti later said credentials stolen in those attacks likely enabled exploitation of the newer CVE-2026-6973 flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcehelpnetsecurity.com
Open sourcekyberturvallisuuskeskus.fi
Open sourcebleepingcomputer.com
Open sourcecvefeed.io
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.