LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-6973: Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 7, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 10, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-6973 to its Known Exploited Vulnerabilities catalog on May 7, 2026, with a federal patch deadline of May 10, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that permits a remotely authenticated administrative user to achieve remote code execution on the affected system. This matters because EPMM servers manage mobile device fleets and hold elevated privileges over enterprise endpoints; successful exploitation can grant an attacker control over device policies, certificates, and connected infrastructure.

How it works

The weakness is classified as CWE-20, improper input validation. In this class of flaw, the application fails to correctly sanitize or constrain data supplied by a user before the data is processed by downstream components. An attacker who already possesses valid administrative credentials can supply crafted input that bypasses expected checks, resulting in execution of arbitrary code on the server. No public details on exact input vectors or payload construction are provided in the summary; confirm mechanics against the vendor advisory.

Am I affected? How to find it in your systems

Ivanti Endpoint Manager Mobile (EPMM) is typically deployed as an on-premises or cloud-hosted server that provisions and monitors mobile devices. Inventory all instances by querying asset management records, package managers, or container registries for the EPMM software. Because no specific versions are stated in the available summary, compare installed builds directly against the vendor advisory. Review administrative access logs for connections from unexpected source addresses and examine process execution telemetry for anomalies originating from the EPMM service account.

How to remediate

If you can't patch immediately

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to subsequent breaches in other environments. You can run a free exposure scan of your email addresses to check whether they appear in known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Endpoint Manager Mobile (EPMM)
WeaknessCWE-20
Added to CISA KEVMay 7, 2026
Federal patch deadlineMay 10, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities