Ivanti disclosed five vulnerabilities in Endpoint Manager Mobile (EPMM), including CVE-2026-6973, an authenticated remote code execution flaw with a CVSS 7.2 score that the company said has been exploited against a very limited number of customers. The issue requires administrative authentication, and Ivanti said organizations that rotated credentials after the earlier January flaws CVE-2026-1281 and CVE-2026-1340 have significantly reduced risk. CERT-SE separately highlighted that CVE-2026-6973 was added to CISA’s Known Exploited Vulnerabilities catalog.
The advisory also covers CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, and CVE-2026-7821, with Ivanti reporting no known exploitation for those issues at disclosure time. According to the vendor and CERT-SE, the additional flaws include weaknesses that can enable administrative privilege gain and unauthenticated certificate access, while CVE-2026-7821 affects only environments using Apple Device Enrollment. Ivanti urged customers to rotate administrative credentials and upgrade EPMM to 12.6.1.1, 12.7.0.1, or 12.8.0.1; it also released compatible Sentry versions, while stating that Sentry itself is not affected.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CERT-SE highlighted Ivanti's disclosure and reported that the actively exploited CVE-2026-6973 had been added to CISA's Known Exploited Vulnerabilities catalog. It also reiterated that affected EPMM versions earlier than 12.6.1.1, 12.7.0.1, and 12.8.0.1 should be updated.
In the same advisory, Ivanti directed customers to update EPMM to versions 12.6.1.1, 12.7.0.1, or 12.8.0.1, which also include fixes for CVE-2026-1281 and CVE-2026-1340. Ivanti also released new Sentry versions for deployment compatibility while noting Sentry itself was not affected.
Ivanti published a security advisory for multiple Endpoint Manager Mobile vulnerabilities, including CVE-2026-6973, and said it was aware of a very limited number of customers exploited through that flaw. The company also stated there was no known customer exploitation at disclosure time for CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, or CVE-2026-7821.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.