Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Could Lovable’s 10% automatic raise be the cure for a toxic culture?

Ivanti EPMM CVE-2026-6973 Active exploit allows RCE to grant administrator-level access

PCPJack Credential Stealer exploits five CVEs to spread like a worm across cloud systems

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Ivanti EPMM CVE-2026-6973 Active exploit allows RCE to grant administrator-level access
Identity

Ivanti EPMM CVE-2026-6973 Active exploit allows RCE to grant administrator-level access

By May 7, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMay 7, 2026Vulnerability/Network Security

Ivanti warns that a new security flaw affecting Endpoint Manager Mobile (EPMM) is being investigated in limited live attacks.

High severity vulnerability CVE-2026-6973 (CVSS score: 7.2) is a case of improper input validation that affects EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1.

This allows “remote authenticated users with administrative access” to remotely execute code, Ivanti said in an advisory published today.

“We are aware that CVE-2026-6973 has been exploited in a very limited number of customers. Administrative authentication is required for successful exploitation. If customers follow Ivanti’s January recommendation to rotate credentials when CVE-2026-1281 and CVE-2026-1340 are exploited, CVE-2026-6973 The risk of it being exploited is significantly reduced.”

At this time, it is unclear who is behind the exploits, whether those attacks were successful, and what the ultimate goal of the attacks was.

Following this development, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) Catalog and required Federal Civilian Executive Branch (FCEB) agencies to patch it by May 10, 2026.

There are also four other flaws patched by Ivanti in EPMM.

CVE-2026-5786 (CVSS Score: 8.8) – Improper access control vulnerability allows remote authenticated attackers to gain administrative access. CVE-2026-5787 (CVSS Score: 8.9) – Improper certificate validation vulnerability allows a remote unauthenticated attacker to impersonate a registered Sentry host and obtain a valid CA-signed client certificate. CVE-2026-5788 (CVSS Score: 7.0) – Improper access control vulnerability that allows remote unauthenticated attackers to call arbitrary methods. CVE-2026-7821 (CVSS Score: 7.4) – Improper certificate validation vulnerability allows a remote unauthenticated attacker to register a device that belongs to a restricted set of unregistered devices, leading to information disclosure about the EPMM appliance and impacting the integrity of newly registered device identities.

“This issue only affects the on-premises EPMM product and does not exist in Ivanti Neurons for MDM, Ivanti’s cloud-based unified endpoint management solution, Ivanti EPM (a similar but different product), Ivanti Sentry, or any other Ivanti product,” the company said.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticlePCPJack Credential Stealer exploits five CVEs to spread like a worm across cloud systems
Next Article Could Lovable’s 10% automatic raise be the cure for a toxic culture?

Related Posts

PCPJack Credential Stealer exploits five CVEs to spread like a worm across cloud systems

May 7, 2026

“Patient Zero” Webinar on Eliminating Stealth Breaches

May 7, 2026

PAN-OS RCE exploit is actively used to allow root access and espionage

May 7, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Could Lovable’s 10% automatic raise be the cure for a toxic culture?

Ivanti EPMM CVE-2026-6973 Active exploit allows RCE to grant administrator-level access

PCPJack Credential Stealer exploits five CVEs to spread like a worm across cloud systems

Google unveils Whoop-like screenless Fitbit Air

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.