Ivanti released security updates for Endpoint Manager Mobile (EPMM) to fix two high-severity vulnerabilities, CVE-2026-6973 and CVE-2026-10727, that could let an authenticated remote attacker achieve remote code execution and privilege escalation. Ivanti said CVE-2026-6973 is a configuration control weakness that allows arbitrary Apache directive injection, while CVE-2026-10727 is an OS command injection flaw that can result in command execution as root. The company said it was not aware of customer exploitation at the time of disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On June 9, 2026, the Canadian Centre for Cyber Security published alert AV26-567 highlighting Ivanti advisories for multiple products, including EPMM and Sentry. The notice urged administrators to review the advisories and apply the required updates.
On 2026-06-09, Ivanti disclosed four vulnerabilities affecting Endpoint Manager Mobile and Ivanti Sentry, including Sentry flaws CVE-2026-10520 and CVE-2026-10523 that could enable administrative takeover and root-level remote code execution. Ivanti released patches for affected versions and said it had not observed exploitation in the wild at disclosure.
On June 9, 2026, Ivanti published a security advisory for Endpoint Manager Mobile addressing CVE-2026-6973 and CVE-2026-10727. The company said the issues were fixed in EPMM versions 12.9.0.1, 12.8.0.3, and 12.7.0.2, and noted it was not aware of customer exploitation at disclosure.
On 2026-05-07, Ivanti disclosed CVE-2026-6973, an actively exploited improper input validation flaw in on-premises Endpoint Manager Mobile that can lead to remote code execution by an authenticated administrator. Ivanti and the Belgian Centre for Cyber Security said a limited number of customers were compromised, and Ivanti released patched EPMM builds while advising organizations to rotate administrative credentials if they may have been stolen.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcelabs.beazley.security
Open sourcecyber.gc.ca
Open sourcehub.ivanti.com
Open sourcezeropath.com
Open sourceforums.ivanti.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.