Skip to content
COOEY

EXPOSURES › CVE-2026-6973

CVE-2026-6973

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-05-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-6973 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildsupply-chain

Ivanti EPMM allows remote code execution for authenticated admins via improper input validation.

This vulnerability enables remote code execution for users with administrative access, posing a severe risk to endpoint management systems in defense organizations. DIB orgs must patch immediately to prevent attackers from leveraging compromised admin credentials to execute arbitrary code on managed endpoints. The active exploitation status indicates this is a current threat vector.

Shame score — Active exploitation of a remote code execution vulnerability in widely deployed endpoint management software.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized