Summary
Ivanti Endpoint Manager Mobile (EPMM) on-premises versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1 contain improper input validation in an administrative management path. An attacker who already has an EPMM administrator account can submit crafted input that reaches vulnerable server-side processing and triggers remote code execution on the appliance. Ivanti says exploitation has been very limited and CISA has listed the CVE in KEV.
Why Planned Fix?
5/6Exploitation Details
Execute arbitrary code on the EPMM appliance with admin privileges.
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Ivanti Endpoint Manager Mobile (EPMM) | before 12.6.1.1, 12.7.0.1, and 12.8.0.1 |
On-premises unified endpoint management platform for managing mobile devices, applications, and content across an enterprise.
Affected ComponentAdministrative web management interface and server-side input validation in the EPMM admin path.
Administrative web management interface and server-side input validation in the EPMM admin path.
Affected Endpoints(1)/mics
Not available
Not available
Upgrade on-premises Ivanti Endpoint Manager Mobile to 12.6.1.1, 12.7.0.1, or 12.8.0.1 to fix CVE-2026-6973.
Upgrade on-premises Ivanti Endpoint Manager Mobile to 12.6.1.1, 12.7.0.1, or 12.8.0.1 to fix CVE-2026-6973.
Probability of exploitation in the next 30 days
Worse than 90% of all CVEs
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Affected Software (CPE) (3)
- •cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*
- •cpe:2.3:a:ivanti:endpoint_manager_mobile:12.7.0.0:*:*:*:*:*:*:*
- •cpe:2.3:a:ivanti:endpoint_manager_mobile:12.8.0.0:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| forums.ivanti.com | May 2026 Security Advisory: Ivanti Endpoint Manager Mobile (EPMM) (Multiple CVEs) |
| www.ivanti.com | January 2026 EPMM Security Update |
| help.ivanti.com | Signing in to the Ivanti EPMM System Manager |
| help.ivanti.com | Port Settings |
| www.cyber.gc.ca | Ivanti security advisory AV26-435 |
| thehackernews.com | Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access |
| cyberscoop.com | Ivanti customers confront yet another actively exploited zero-day |
Priority History
Initial analysis