CVE-2026-6973
high
KEV
CVSS v3
7.2
CVSS v2
—
VIR risk
8.7
Description
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
CISA KEV
- Vendor
- Ivanti
- Product
- Endpoint Manager Mobile (EPMM)
- Due date
- 2026-05-10
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2026-6973
Vendor advisory: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75 — https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US
Exploits
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ivanti | endpoint_manager_mobile | {"endExcluding":"12.6.1.1"} | 12.6.1.1 |
| ivanti | endpoint_manager_mobile | 12.7.0.0 | |
| ivanti | endpoint_manager_mobile | 12.8.0.0 | |
References
- https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-6973
- https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2026-6973
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.