• News/
  • https://www.bleepingcomputer.com/news/security/cisa-gives-feds-four-days-to-patch-ivanti-flaw-exploited-as-zero-day/

CISA gives feds four days to patch Ivanti flaw exploited as zero-day

BleepingComputer
·
Sergiu Gatlan
·
Published May 8, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their networks against a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that has been exploited in zero-day attacks. Tracked as CVE-2026-6973, this security flaw allows attackers with administrative privileges to execute arbitrary code remotely on systems running EPMM 12.8.0.0 and earlier. In a Thursday security advisory, Ivanti told customers they can secure their appliances by installing Ivanti EPMM 12.6.1.1, 12.7.0.1, and 12.8.0.1, and advised them to review accounts with Admin rights and rotate those credentials where necessary. "At the time of disclosure, we are aware of very limited exploitation of CVE-2026-6973, which requires admin authentication for successful exploitation. We are not aware of any customers being exploited by the other vulnerabilities disclosed today," it said. "The issues only affect the on-prem EPMM product, and are not present in Ivanti Neurons for MDM, Ivanti's cloud-based unified endpoint management solution, Ivanti EPM (a similarly named, but different product), Ivanti Sentry, or any other Ivanti products." Nonprofit security organization Shadowserver now tracks over 800 Ivanti EPMM appliances exposed online. However, there is no information on how many have already been patched against the CVE-2026-6973 vulnerability. ​​​On Thursday, CISA added the security flaw to its list of vulnerabilities exploited in ...

Read full article

Affected Software

1 affected component
Ivanti Endpoint Manager Mobile (EPMM)<=12.8.0.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a high-severity vulnerability in Ivanti Endpoint Manager Mobile that federal agencies need to patch urgently due to its exploitation in zero-day attacks.

2

What security implications are discussed?

The article highlights the risk of exploitation of a critical vulnerability, which could lead to unauthorized access or control over affected systems.

3

What specific vulnerability is mentioned in the article?

The vulnerability is tracked as CVE-2026-6973, which poses significant risks to networks using Ivanti Endpoint Manager Mobile.

4

What is the deadline set by CISA for federal agencies to address this issue?

CISA has given federal agencies a four-day deadline to patch the vulnerability.

5

What product is affected by the vulnerability discussed in the article?

The affected product is Ivanti Endpoint Manager Mobile (EPMM).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203