- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,653
The list of victims grows faster than official patches.
Ivanti customers again faced an attack through a product that has repeatedly fallen into the center of high-profile incidents. This time, attackers use a previously unknown vulnerability in Ivanti Endpoint Manager Mobile, used to protect and manage mobile devices on the perimeter of corporate networks.
The company warned about CVE-2026-6973 Thursday, May 7. The error is associated with incorrect checking of input data and allows you to remotely execute the code, but the administrator rights in the EPMM need to attack. According to Ivanti, at the time of disclosure, the company knew only about the very limited exploitation of the vulnerability in real attacks. When the first incidents began and how many customers were injured, Ivanti did not specify.
CISA Agency CVE-2026-6973 in the catalog of known exploited vulnerabilities a few hours after the publication of the ballot. Ivanti also released updates for this error and several other high-risk vulnerabilities in EPMM. The company said that some of the problems were found by internal detection systems, including using AI and subsequent inspection by specialists, and the former employee transferred one vulnerability.
Ivanti attributes the risk of a new attack with the consequences of January incidents, when attackers exploited critical vulnerabilities CVE-2026-1281 and CVE-2026-1340 in the same product. Then the attacks affected almost 100 organizations, including the Dutch data protection body and the Dutch Judiciary Council. The company believes that customers who changed EPMM’s accounting data after January recommendations have significantly reduced the
Caitlin Condon, VulnCheck’s vice president of security research, believes that the requirement of administrative rights may indicate the use of CVE-2026-6973 as part of the attack chain after initial penetration in another way. According to her, the previous vulnerabilities in the EPMM were more dangerous at the initial stage, since they allowed remote operation without authentication.
Ivanti’s problems have long attracted the attention of network defenders. Since the end of 2021, CISA has added 34 errors in the company’s products to the catalog of exploited vulnerabilities. Over the past two years, the attackers have used at least 22 vulnerabilities Ivanti, including five problems in EPMM over the past year.
Ivanti Security Director Daniel Spicer has previously explained the large number of vulnerabilities disclosed by the company’s more open policy. Ivanti claims that it continues to strengthen the safety program of products, quickly look for errors and disclose information about the risks to customers.
Ivanti customers again faced an attack through a product that has repeatedly fallen into the center of high-profile incidents. This time, attackers use a previously unknown vulnerability in Ivanti Endpoint Manager Mobile, used to protect and manage mobile devices on the perimeter of corporate networks.
The company warned about CVE-2026-6973 Thursday, May 7. The error is associated with incorrect checking of input data and allows you to remotely execute the code, but the administrator rights in the EPMM need to attack. According to Ivanti, at the time of disclosure, the company knew only about the very limited exploitation of the vulnerability in real attacks. When the first incidents began and how many customers were injured, Ivanti did not specify.
CISA Agency CVE-2026-6973 in the catalog of known exploited vulnerabilities a few hours after the publication of the ballot. Ivanti also released updates for this error and several other high-risk vulnerabilities in EPMM. The company said that some of the problems were found by internal detection systems, including using AI and subsequent inspection by specialists, and the former employee transferred one vulnerability.
Ivanti attributes the risk of a new attack with the consequences of January incidents, when attackers exploited critical vulnerabilities CVE-2026-1281 and CVE-2026-1340 in the same product. Then the attacks affected almost 100 organizations, including the Dutch data protection body and the Dutch Judiciary Council. The company believes that customers who changed EPMM’s accounting data after January recommendations have significantly reduced the
Caitlin Condon, VulnCheck’s vice president of security research, believes that the requirement of administrative rights may indicate the use of CVE-2026-6973 as part of the attack chain after initial penetration in another way. According to her, the previous vulnerabilities in the EPMM were more dangerous at the initial stage, since they allowed remote operation without authentication.
Ivanti’s problems have long attracted the attention of network defenders. Since the end of 2021, CISA has added 34 errors in the company’s products to the catalog of exploited vulnerabilities. Over the past two years, the attackers have used at least 22 vulnerabilities Ivanti, including five problems in EPMM over the past year.
Ivanti Security Director Daniel Spicer has previously explained the large number of vulnerabilities disclosed by the company’s more open policy. Ivanti claims that it continues to strengthen the safety program of products, quickly look for errors and disclose information about the risks to customers.