← Back to browse · API

CVE-2026-6973

Severity
HIGH
CVSS
7.2
EPSS
0.34454
Risk score
65.86
CISA KEV
Yes
PoC
No
Published
2026-05-07
Modified
2026-06-11
First seen
2026-08-07
Aliases
EUVD-2026-28396, GHSA-36FG-FFJJ-H5P6
Products
Ivanti:Endpoint Manager Mobile (EPMM), Ivanti:Endpoint Manager Mobile patch: 12.6.1.1, Ivanti:Endpoint Manager Mobile patch: 12.7.0.1, Ivanti:Endpoint Manager Mobile patch: 12.8.0.1
Sources
cisa.gov CVE-2026-6973
euvd EUVD-2026-28396

Description

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

References