Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogcredential-access-methodinternet-exposed-service

Ivanti EPMM Zero-Day CVE-2026-6973 Exploited via Stolen Admin Credentials

Updated 1mo agoFirst seen May 7, 202613 sources

Ivanti disclosed active exploitation of CVE-2026-6973, a high-severity improper input validation flaw in on-premises Endpoint Manager Mobile (EPMM) that allows remote code execution when used with administrator authentication. The company said exploitation has been limited to a small number of customers and assessed with high confidence that attackers are using administrator credentials stolen during earlier January attacks involving CVE-2026-1281 and CVE-2026-1340. Affected versions are EPMM releases prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1; Ivanti said Neurons for MDM, EPM, Sentry, and other products are not affected.

Ivanti also patched four additional high-severity EPMM flaws—CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, and CVE-2026-7821—covering certificate validation and access-control weaknesses that could enable host impersonation, unauthorized access, arbitrary method invocation, and unauthorized device enrollment, though the vendor said it has no evidence those bugs were exploited. CISA added CVE-2026-6973 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to remediate by May 10, 2026, while national cyber agencies in Canada and Finland urged immediate patching. Ivanti advised customers to rotate EPMM administrator credentials, review privileged accounts, hunt for compromise artifacts such as webshells and reverse shells, and reduce public exposure of management interfaces; internet scans have identified more than 850 exposed EPMM instances, mainly in Europe and North America.

Share:
Ivanti EPMM Zero-Day CVE-2026-6973 Exploited via Stolen Admin Credentials
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 7, 20262mo ago

CISA adds CVE-2026-6973 to KEV and sets May 10 remediation deadline

On May 7, 2026, CISA added Ivanti EPMM flaw CVE-2026-6973 to its Known Exploited Vulnerabilities catalog after reports of active exploitation. Under Binding Operational Directive 22-01, federal agencies were ordered to remediate the issue by May 10, 2026.

Ivanti links new zero-day exploitation to credentials stolen in January

On May 7, 2026, Ivanti assessed with high confidence that attackers exploiting CVE-2026-6973 were using administrator credentials stolen during the January attacks on CVE-2026-1281 and CVE-2026-1340. The company advised customers to rotate EPMM admin credentials, review privileged accounts, and check for compromise artifacts.

Ivanti patches five EPMM flaws and warns CVE-2026-6973 is exploited

On May 7, 2026, Ivanti published a security advisory for five EPMM vulnerabilities, including actively exploited RCE flaw CVE-2026-6973, and released fixed versions 12.6.1.1, 12.7.0.1, and 12.8.0.1. Ivanti said exploitation was limited, required administrator authentication, and affected only on-premises EPMM, not other Ivanti products.

Apr 1, 20263mo ago

CISA orders federal agencies to secure January Ivanti EPMM flaws

In April 2026, CISA directed U.S. federal civilian agencies to secure affected Ivanti EPMM systems within four days following the earlier January zero-day activity. This marked formal U.S. government response to the prior EPMM exploitation.

Jan 1, 20266mo ago

Ivanti discloses January EPMM zero-days CVE-2026-1281 and CVE-2026-1340

In January 2026, Ivanti disclosed and responded to exploitation of EPMM vulnerabilities CVE-2026-1281 and CVE-2026-1340. Ivanti later said credentials stolen in those attacks likely enabled exploitation of the newer CVE-2026-6973 flaw.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Ivanti EPMM Zero-Day CVE-2026-6973 Exploited via Stolen Admin Credentials | Mallory