Ivanti Patches EPMM Zero-Day Exploited in Targeted Attacks

Summary

Ivanti has released a patch for a high-severity zero-day vulnerability in its Endpoint Manager Mobile (EPMM) product. This vulnerability, identified as CVE-2026-6973, allows an attacker with administrative privileges to execute arbitrary code.

IFF Assessment

FOE

The exploitation of a zero-day vulnerability that allows arbitrary code execution is bad news for defenders, as it presents an immediate threat that can be leveraged by attackers.

Severity

7.2 High

CISA KEV: Listed as actively exploited. Federal patch due: May 10, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching Ivanti EPMM systems immediately to mitigate the risk of exploitation. This incident highlights the ongoing threat of zero-day vulnerabilities in widely used management software and the importance of timely security updates.

Read Full Story →