Ivanti Security Advisories guidance
Our top priority is the security of our customers, and we expect that this work will naturally increase the number of vulnerabilities found, fixed, and disclosed.
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
CISA lists CVE-2026-6973 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Ivanti Endpoint Manager Mobile (EPMM).
Public exploit: Not collected. Review the linked vendor advisory and apply the mitigation or fixed release for your affected product.
Our top priority is the security of our customers, and we expect that this work will naturally increase the number of vulnerabilities found, fixed, and disclosed.
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.