Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Authenticated RCE Zero-Day — CVE-2026-6973 (CISA KEV, Active Exploitation) — Threadlinqs Intelligence
As of 2026-05-30, Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Authenticated RCE Zero-Day — CVE-2026-6973 (CISA KEV, Active Exploitation) is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-0477 · Severity: HIGH · CVSS: 7.2 · Status: ACTIVE · Category: VULNERABILITY
Ivanti disclosed CVE-2026-6973, a CWE-20 Improper Input Validation flaw in on-prem Endpoint Manager Mobile (EPMM) 12.8.0.0 and earlier that lets a remotely authenticated administrator achieve
CVE-2026-6973 is the actively exploited zero-day in Ivanti's May 2026 Endpoint Manager Mobile (EPMM) security advisory. The vulnerability is classified as CWE-20 Improper Input Validation, scored CVSS 3.1 7.2 HIGH (vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), and lives in unspecified administrative endpoints of the EPMM core appliance. A remote attacker who already holds administrative access to the EPMM web console can submit crafted input that bypasses server-side validation and is interpreted by the underlying runtime, yielding arbitrary code execution as the EPMM service account on the appliance host. EPMM appliances run as the central trust anchor for enterprise mobile fleets — they hold MDM enrollment certificates, push notification keys, Active Directory bind credentials, certificate authority private keys, VPN profiles, Wi-Fi credentials, and policy payloads — so RCE on the core is a high-value pivot point into both the corporate network and tens of thousands of managed mobile endpoints.
Ivanti shipped CVE-2026-6973 alongside four other CVEs in the same May 2026 EPMM advisory: CVE-2026-5786 (CWE-284 Improper Access Control allowing an authenticated user to gain administrative access), CVE-2026-5787 (CWE-295 Improper Certificate Validation enabling impersonation of registered Sentry hosts and theft of valid CA-signed certificates), CVE-2026-5788 (CWE-284 Improper Access Control allowing an unauthenticated remote attacker to invoke arbitrary methods on the EPMM core), and CVE-2026-7821 (CWE-295 Improper Certificate Validation enabling enrollment of devices belonging to a restricted set of unenrolled users). The most plausible end-to-end exploit chain stitches CVE-2026-5788 (unauthenticated method invocation) with CVE-2026-5786 (privilege escalation to administrator) and finally CVE-2026-6973 (administrator-authenticated RCE), giving a fully unauthenticated remote code execution path against any internet-exposed unpatched EPMM core. Ivanti's explicit recommendation to rotate EPMM administrative credentials post-patch — beyond the standard "apply patch" guidance — strongly implies that observed in-the-wild operators are reusing or harvesting EPMM admin credentials, consistent with the credential-theft tradecraft seen in the January 2026 EPMM zero-days CVE-2026-1281 and CVE-2026-1340.
CISA added CVE-2026-6973 to the Known Exploited Vulnerabilities (KEV) Catalog on 2026-05-07, the same day Ivanti disclosed the advisory, triggering Binding Operational Directive 22-01 and a 21-day federal civilian remediation deadline. The Shadowserver Foundation tracks roughly 850+ internet-exposed Ivanti EPMM fingerprints globally — 508 in Europe, 182 in North America — most of which remain attributable to a small set of repeatedly targeted regulated sectors (government, defense industrial base, financial services, healthcare, telecom, education). Ivanti has not publicly attributed the activity. However, the EPMM product line has a sustained history of zero-day exploitation by the China-nexus UNC5221 cluster (Ivanti Connect Secure 2024, EPMM January 2026 CVE-2026-1281/1340), and the limited-scope, credential-harvesting tradecraft seen here is consistent with that actor cluster pending public attribution. Patches are available in EPMM 12.6.1.1, 12.7.0.1, and 12.8.0.1; cloud Ivanti Neurons for MDM, Ivanti EPM (desktop), and Ivanti Sentry are explicitly not affected.
Detection-relevant indicators include unexpected child processes spawned by EPMM service users (typically tomcat/jboss-style runtimes), abnormal outbound connections from EPMM cores to non-corporate infrastructure, modification of EPMM webapp directories outside scheduled patch windows, creation of new administrator accounts in the EPMM console, and Sentry impersonation events surfaced in Ivanti audit logs (relevant to CVE-2026-5787). Defenders running on-prem EPMM should patch immediately, rotate all EPMM admin and service account credentials post-patch, audit administrative ac
Target sectors: government, defense industrial base, financial services, healthcare, telecommunications, education, critical infrastructure
Target regions: Europe, North America, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-6973, T1595, T1595.002, T1587.004, T1190, T1078, T1059, T1059.004, T1203, T1505.003, T1136.001