SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-6973

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

KEVHIGH 7.2EPSS 34.5%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 May 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
34.45% probability · 98th percentile
CISA KEV
Listed 7 May 2026 · due 10 May 2026
Weakness
CWE-20
Affected
ivanti/endpoint manager mobile
Source
3c1d8aa1-5a33-4ea4-8992-aadd6440af75

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2026-6973

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.