The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their networks against a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that has been exploited in zero-day attacks. Tracked as CVE-2026-6973, this security flaw allows attackers with administrative privileges to execute arbitrary code remotely on systems running EPMM 12.8.0.0 and earlier. In a Thursday security advisory, Ivanti told customers they can secure their appliances by installing Ivanti EPMM 12.6.1.1, 12.7.0.1, and 12.8.0.1, and advised them to review accounts with Admin rights and rotate those credentials where necessary. "At the time of disclosure, we are aware of very limited exploitation of CVE-2026-6973, which requires admin authentication for successful exploitation. We are not aware of any customers being exploited by the other vulnerabilities disclosed today," it said. "The issues only affect the on-prem EPMM product, and are not present in Ivanti Neurons for MDM, Ivanti's cloud-based unified endpoint management solution, Ivanti EPM (a similarly named, but different product), Ivanti Sentry, or any other Ivanti products." Nonprofit security organization Shadowserver now tracks over 800 Ivanti EPMM appliances exposed online. However, there is no information on how many have already been patched against the CVE-2026-6973 vulnerability. On Thursday, CISA added the security flaw to its list of vulnerabilities exploited in ...
CISA gives feds four days to patch Ivanti flaw exploited as zero-day
BleepingComputer
·Published May 8, 2026
·Updated
Affected Software
1 affected component
Ivanti Endpoint Manager Mobile (EPMM)<=12.8.0.0
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical security vulnerability in Ivanti Endpoint Manager Mobile and the urgency with which U.S. federal agencies must respond.
2
What security implications are discussed?
The article emphasizes a high-severity exploit that could compromise federal networks if the vulnerability is not patched promptly.
3
What products or software are affected?
The affected software is Ivanti Endpoint Manager Mobile (EPMM), specifically version 12.8.0.0 and below.
4
What action has CISA mandated for federal agencies?
CISA has mandated that federal agencies must patch the Ivanti vulnerability within four days to secure their systems.
5
Why is the vulnerability considered a zero-day?
It is labeled a zero-day because it was actively exploited before a public disclosure or patch was available.