Ivanti reports that a high-severity vulnerability in Endpoint Manager Mobile (EPMM) is being exploited in limited “in-the-wild” zero-day activity. The issue, tracked as CVE-2026-6973, is linked to improper input validation in EPMM and is described as enabling remote code execution (RCE). According to the reporting, the flaw affects EPMM versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1. The affected functionality can be reached by an attacker who is remotely authenticated and has administrative access, allowing arbitrary code execution on vulnerable systems. Ivanti’s advisory and subsequent coverage indicate the exploitation is targeted and involves a very limited number of customers, rather than widespread abuse. Multiple outlets also note that Ivanti has released fixes and that customers are advised to apply the updated versions to remediate the risk. SecurityWeek and Help Net Security describe the vulnerability as a zero-day that is actively used in targeted attacks, while other coverage emphasizes Ivanti’s customer warning to patch promptly.
Ivanti says CVE-2026-6973 EPMM flaw is exploited in limited zero-day attacks
Ivanti reports that a high-severity vulnerability in Endpoint Manager Mobile (EPMM) is being exploited in limited “in-the-wild” zero-day activity. The issue, tracked as CVE-2026-6973, is linked to imp...
- Ivanti warns of active zero-day exploitation of CVE-2026-6973 in Endpoint Manager Mobile (EPMM).
- CVE-2026-6973 is a high-severity remote code execution issue caused by improper input validation.
- The vulnerability affects EPMM versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1.
- Exploitation involves remote access by a remotely authenticated attacker with administrative privileges.
- Ivanti issues fixes and advises customers to patch; reports describe exploitation as limited and targeted.
Ivanti has released fixes for 5 high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) solution, one of which (CVE-2026-6973) has being exploited as a zero-day by attackers. “We are aware of a very limited number of customers exploited with CVE-2026-6973,” the company said in a security advisory published on Thursday. About CVE-2026-6973 CVE-2026-6973 is caused by improper input validation and allows remote attackers with administrative privileges to execute arbitrary code on vulnerable instances. “If customers … More → The post Ivanti EPMM vulnerability exploited in zero-day attacks (CVE-2026-6973) appeared first on Help Net Security.
3 months agoCVE-2026-6973 is a high-severity vulnerability that allows an attacker who has admin privileges to execute arbitrary code. The post Ivanti Patches EPMM Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek.
3 months agoIvanti is warning that a new security flaw impacting Endpoint Manager Mobile (EPMM) has been explored in limited attacks in the wild. The high-severity vulnerability, CVE-2026-6973 (CVSS score: 7.2), is a case of improper input validation affecting EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1. It allows "a remotely authenticated user with administrative access to achieve remote code
3 months agoIvanti warned customers today to patch a high-severity remote code execution vulnerability in Endpoint Manager Mobile (EPMM) exploited in zero-day attacks. [...]
3 months ago
Sinn Féin calls for ferry passport rule change to cover Northern Ireland
Ferry passengers travelling between Ireland and Britain will need a valid passport from the end of next month, according...
Teenager charged over e-scooter crash injuring 9-year-old boy in Kildare
A teenager is charged in connection with a crash involving a high-powered e-scooter that leaves a nine-year-old boy with...
US colleges expand 90-credit three-year bachelor’s degrees as debate continues
More U.S. colleges are offering three-year bachelor’s degree options that compress study time by requiring fewer credits...