CVE-2026-6973
9.5 CISA KEVIvanti · Endpoint Manager Mobile (EPMM)
An improper input validation vulnerability in Ivanti EPMM allows an authenticated administrator to execute arbitrary code on the system.
Executive summary
A critical input validation vulnerability in Ivanti Endpoint Manager Mobile is currently under active exploitation and requires immediate administrative action to prevent remote code execution.
Vulnerability
This vulnerability involves improper input validation (CWE-20) that can be leveraged by a remotely authenticated user with administrative privileges to achieve remote code execution.
Business impact
The ability for an administrative user to execute remote code on the EPMM appliance presents a significant threat to organizational mobile device management security. An attacker who gains these privileges could manage, track, or compromise all enrolled mobile devices, leading to widespread corporate data theft and surveillance. With a CVSS score of 9.5, the risk to the confidentiality and integrity of the mobile fleet is extreme.
Remediation
Immediate Action: Upgrade Ivanti Endpoint Manager Mobile to version 12.6.1.1, 12.7.0.1, or 12.8.0.1 as specified by the vendor advisory.
Proactive Monitoring: Monitor administrative access logs for unusual activity or unauthorized configuration changes that could indicate an attacker is attempting to leverage this vulnerability.
Compensating Controls: Restrict administrative console access to trusted IP addresses and implement multi-factor authentication for all administrative accounts to mitigate the potential for credential misuse.
Exploitation status
Public Exploit Available: No confirmed public exploit is available in our curated data sources at this time.
Analyst recommendation
Due to the confirmed active exploitation of this flaw, administrators must prioritize the update to the fixed versions. Ensure that all administrative access to the EPMM interface is strictly controlled and audited to prevent further exploitation of this vulnerability.