What is CVE-2026-6973?
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
Timeline
- 2026-05-07Published to the U.S. National Vulnerability Database (NVD)
- 2026-05-07Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-05-08First covered in a defend.network daily briefing
- 2026-05-10CISA federal remediation deadline (BOD 22-01)
- 2026-06-17NVD record last updated
CISA Known Exploited Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
Affected product
Ivanti Endpoint Manager Mobile (EPMM)
Remediation Steps
- Apply Ivanti emergency security patches released for EPMM immediately
- If patching is not immediately possible, isolate EPMM servers from network access
- Implement multi-factor authentication for all EPMM administrative accounts
- Monitor authentication logs for suspicious activity and unauthorized access attempts
- Enable endpoint detection and response (EDR) monitoring on all connected devices
References
- https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-6973
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.ivanti.com/security
- https://nvd.nist.gov/vuln/detail/CVE-2026-6973
Referenced in our briefings & reports
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.