Ivanti reports that a high-severity vulnerability in Endpoint Manager Mobile (EPMM) is being exploited in limited “in-the-wild” zero-day activity. The issue, tracked as CVE-2026-6973, is linked to improper input validation in EPMM and is described as enabling remote code execution (RCE). According to the reporting, the flaw affects EPMM versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1. The affected functionality can be reached by an attacker who is remotely authenticated and has administrative access, allowing arbitrary code execution on vulnerable systems. Ivanti’s advisory and subsequent coverage indicate the exploitation is targeted and involves a very limited number of customers, rather than widespread abuse. Multiple outlets also note that Ivanti has released fixes and that customers are advised to apply the updated versions to remediate the risk. SecurityWeek and Help Net Security describe the vulnerability as a zero-day that is actively used in targeted attacks, while other coverage emphasizes Ivanti’s customer warning to patch promptly.