CVE-2026-6973

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated...

Basic Information

CVE State
PUBLISHED
Reserved Date
April 24, 2026
Published Date
May 07, 2026
Last Updated
May 08, 2026
Vendor
Ivanti
Product
Endpoint Manager Mobile
Description
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
Tags
cisa

CVSS Scores

CVSS v3.1

7.2 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 13:26:33 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 13:26:33 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel