CVE-2026-6973
KEVlargeAuthenticated RCE in Ivanti Endpoint Manager Mobile (EPMM)
CISA: Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation flaw (CWE-20) that allows a remotely authenticated user with administrative access to achieve remote code execution on the server. An attacker triggers it by sending crafted input to the EPMM management interface after authenticating with administrative credentials, so compromise or misuse of an admin account is the likely path to exploitation. Successful exploitation yields code execution on the EPMM server, giving an attacker a foothold in the organization's mobile device management infrastructure and potential access to data managed through it. Any organization running Ivanti EPMM, typically enterprises using it as their MDM platform, is affected; the available data does not specify affected version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-07, confirming active exploitation (ransomware use unknown), and it carries a high 34.5% EPSS for exploitation in the next 30 days.
What to do: Update EPMM to the patched release identified in Ivanti's advisory, as required under CISA KEV and BOD 22-01 for federal agencies. Until patched, restrict and audit administrative access to EPMM, review authentication and admin-activity logs for signs of abuse, and limit exposure of the management interface to trusted networks.
| Ivanti Endpoint Manager Mobile (EPMM) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
- Affected
- Ivanti Endpoint Manager Mobile (EPMM)
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- ivanti
- Products
- endpoint manager mobile
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H