
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6973 is an Improper Input Validation vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows a remotely authenticated attacker with administrative access to achieve remote code execution (RCE) by injecting arbitrary Apache directives. It affects EPMM versions prior to 12.6.1.1, 12.7.0.2, 12.8.0.3, and 12.9.0.1. The vulnerability was publicly disclosed on May 7, 2026, and was immediately added to the CISA Known Exploited Vulnerabilities (KEV) catalog the same day with a remediation deadline of May 10, 2026. It carries a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory, CISA KEV).
The vulnerability is classified under CWE-20 (Improper Input Validation) and CWE-15 (External Control of System or Configuration Setting). An authenticated administrator can supply malicious input to an EPMM administrative API endpoint that is not properly sanitized, enabling injection of arbitrary Apache web server directives into the server configuration. This configuration injection ultimately leads to remote code execution on the underlying server. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require high privileges (administrative credentials) (GitHub Advisory, Feedly). A technical deep-dive was published by ZeroPath (ZeroPath Blog).
Successful exploitation grants the attacker remote code execution on the EPMM server with the privileges of the service account, resulting in full compromise of confidentiality, integrity, and availability. An attacker could exfiltrate sensitive mobile device management (MDM) data — including enrolled device inventories, user credentials, and enterprise configurations — and use the compromised EPMM server as a pivot point for lateral movement into the broader enterprise network. Reports indicate that in observed attacks, credentials stolen from prior January 2026 intrusions were leveraged to authenticate and exploit this vulnerability, amplifying the risk for organizations already affected by earlier Ivanti compromises (The Hacker News, Dark Web Informer).
CVE-2026-6973 was exploited as a zero-day in the wild at the time of disclosure, with Ivanti confirming awareness of a "very limited number" of targeted attacks. The vulnerability was added to the CISA KEV catalog on May 7, 2026, with a four-day remediation deadline for federal agencies (CISA KEV). Belgium's Centre for Cybersecurity (CCB) issued a specific warning about active exploitation (CCB Belgium). No public proof-of-concept exploit code has been confirmed, though the vulnerability has been described as already weaponized in targeted attacks. The EPSS score is approximately 6.4% (with some sources citing up to 5.5% at the 90th percentile), reflecting meaningful exploitation probability. Approximately 850 internet-exposed EPMM servers were identified as potentially vulnerable at the time of disclosure.
httpd.conf or .htaccess files) on the EPMM server; presence of web shells or unauthorized scripts in the EPMM web root or Apache directories.httpd) process, such as shell interpreters (/bin/bash, sh, cmd.exe), network utilities (curl, wget, nc), or scripting engines; unexpected cron jobs or scheduled tasks created under the EPMM service account.Ivanti has released patched versions addressing CVE-2026-6973: 12.6.1.1, 12.7.0.2, 12.8.0.3, and 12.9.0.1. Organizations should upgrade to the appropriate fixed version immediately. As interim measures, restrict administrative access to EPMM to trusted IP ranges only, enforce multi-factor authentication for administrative accounts, and rotate any administrative credentials that may have been exposed in prior incidents. CISA mandated that federal agencies apply mitigations by May 10, 2026 per BOD 22-01; organizations unable to patch should consider discontinuing use of the product (CISA KEV, Ivanti Advisory).
Ivanti publicly acknowledged active exploitation, stating awareness of "a very limited number" of targeted attacks at the time of disclosure (Security Week). The vulnerability generated significant coverage across the security community, with CyberScoop, The Hacker News, BleepingComputer, and Help Net Security all publishing detailed reports within hours of disclosure (The Hacker News, CyberScoop). Security researchers on Reddit's r/blueteamsec and r/SecOpsDaily noted the pattern of repeated Ivanti zero-days and the reuse of previously stolen credentials as particularly concerning. Belgium's CCB issued a formal warning, and Canada's CCCS published advisory AV26-435, reflecting international concern about the vulnerability's exploitation scope (CCB Belgium). Proofpoint later included CVE-2026-6973 in a broader analysis of 2026 vulnerability exploitation trends, noting it fit a recurring playbook of Ivanti product targeting (Proofpoint).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."