The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their networks against a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that has been exploited in zero-day attacks. Tracked as CVE-2026-6973, this security flaw allows attackers with administrative privileges to execute arbitrary code remotely on systems running EPMM 12.8.0.0 and earlier. In a Thursday security advisory, Ivanti told customers they can secure their appliances by installing Ivanti EPMM 12.6.1.1, 12.7.0.1, and 12.8.0.1, and advised them to review accounts with Admin rights and rotate those credentials where necessary. "At the time of disclosure, we are aware of very limited exploitation of CVE-2026-6973, which requires admin authentication for successful exploitation. We are not aware of any customers being exploited by the other vulnerabilities disclosed today," it said. "The issues only affect the on-prem EPMM product, and are not present in Ivanti Neurons for MDM, Ivanti's cloud-based unified endpoint management solution, Ivanti EPM (a similarly named, but different product), Ivanti Sentry, or any other Ivanti products." Nonprofit security organization Shadowserver now tracks over 800 Ivanti EPMM appliances exposed online. However, there is no information on how many have already been patched against the CVE-2026-6973 vulnerability. On Thursday, CISA added the security flaw to its list of vulnerabilities exploited in ...
CISA gives feds four days to patch Ivanti flaw exploited as zero-day
BleepingComputer
·Sergiu Gatlan
·Published May 8, 2026
·Updated
Affected Software
1 affected component
Ivanti Endpoint Manager Mobile (EPMM)<=12.8.0.0
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a high-severity vulnerability in Ivanti Endpoint Manager Mobile that federal agencies need to patch urgently due to its exploitation in zero-day attacks.
2
What security implications are discussed?
The article highlights the risk of exploitation of a critical vulnerability, which could lead to unauthorized access or control over affected systems.
3
What specific vulnerability is mentioned in the article?
The vulnerability is tracked as CVE-2026-6973, which poses significant risks to networks using Ivanti Endpoint Manager Mobile.
4
What is the deadline set by CISA for federal agencies to address this issue?
CISA has given federal agencies a four-day deadline to patch the vulnerability.
5
What product is affected by the vulnerability discussed in the article?
The affected product is Ivanti Endpoint Manager Mobile (EPMM).