← Back to CVE intelligence
CVE intelligenceCISA KEV

CVE-2026-6973

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Published May 7, 2026Sources checked Sep 29, 2026
7.2HIGHCVSS out of 10
What this means

Actively exploited

CISA lists CVE-2026-6973 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Ivanti Endpoint Manager Mobile (EPMM).

  • Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Public exploit: Not collected. Review the linked vendor advisory and apply the mitigation or fixed release for your affected product.

What to do next

Remediation and response

Ivanti Security Advisories guidance

Our top priority is the security of our customers, and we expect that this work will naturally increase the number of vulnerabilities found, fixed, and disclosed.

CISA KEVListedObserved exploitation
EPSS2.5%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-6973?

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.