Description
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Critical Vulnerabilities Patched in Fortinet, Ivanti Productsen-us·SecurityWeek· Patch FortiSandbox rce
- High-Severity Vulnerabilities Addressed in Endpoint Manager Mobileen-us·Daily CyberSecurity (securityonline.info)· Patch Ivanti Endpoint Manager Mobile (EPMM) rce
- Топ самых интересных CVE за май 2026 годаru·Хабр — Информационная безопасность·
- 11th May – Threat Intelligence Reporten-us·Check Point Research· Roundup MOVEit Automation ShinyHunters
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-6973 and every CVE in our database. Create a free account — no credit card required.
Create Free Account