Input-validation vulnerability in Ivanti EPMM (CVE-2026-6973) — remote code execution by an authenticated administrator
Ivanti Endpoint Manager Mobile (EPMM), a mobile-device management product, has an improper-input-validation vulnerability that lets a remotely authenticated user with administrative access achieve remote code execution (RCE). CISA listed it as known-exploited (KEV) (CVSS 7.2 High).
Key facts
- CVE IDCVE-2026-6973
- CVSS base score7.2 HIGH
- CVSS vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Affected (vendor / product)Ivanti Endpoint Manager Mobile (EPMM)
- CWECWE-20
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-05-10 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Improper input validation (CWE-20) in Ivanti EPMM (mobile-device management; formerly MobileIron)
- A remotely authenticated user with admin access can achieve remote code execution (RCE)
- Requires auth/admin so CVSS is 7.2 (High), but impact is large given it is a management platform
- Ivanti products repeatedly appear in KEV = favored targets. Listed in CISA KEV = exploitation confirmed
- Response: fix per Ivanti; minimize console exposure and protect admin accounts
- Of the 1,687 records held as of 2026-09-01, Ivanti accounts for 35, led by EPMM and Pulse Connect Secure at 7 each.
1The Ivanti Endpoint Manager flaw
CVE-2026-6973 is an improper-input-validation vulnerability (CWE-20) in Ivanti Endpoint Manager Mobile (EPMM, an MDM/EMM product for managing enterprise mobile devices; formerly MobileIron Core). It was added to CISA's KEV catalog on May 7, 2026.
2Abuse by an administrator-level user
Per NVD, a remotely authenticated user with administrative access can exploit it to achieve remote code execution (RCE). Because the attack requires authentication and admin privileges, the bar is higher than for unauthenticated flaws. Still, a management platform like EPMM is the linchpin controlling many mobile devices across an organization, so allowing code execution there has large impact.
3Why Ivanti products keep being targeted
Ivanti products (EPMM/MobileIron, Connect Secure, etc.) have repeatedly appeared in KEV in recent years, suggesting they are assets attackers favor. Even though authentication is required, given the risk of credential theft or insider/contractor abuse, a known-exploited KEV listing pushes for prompt action.
4What Ivanti's 35 records divide into
Ivanti sits among the leading vendors in the KEV records this site holds. Split by product name, products handling the perimeter and endpoint management line up.
Of the 1,687 records held as of 2026-09-01, Ivanti accounts for 35. Those product names carry variants: Cloud Services Appliance (CSA) and Cloud Services Appliance, and Connect Secure and Policy Secure against Connect Secure, Policy Secure, and ZTA Gateways, appear as separate names. The pattern of products handling the perimeter and management being targeted repeatedly can be read from the sequence of records.
Why it matters
RCE on a mobile-management platform (EPMM) — authentication is required, but the impact is large. Ivanti products repeatedly enter KEV, so users should enforce diligent patching, minimize console exposure, and protect credentials.
FAQ
What is EPMM?
Is it low risk because authentication is required?
What should I do?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).