{"id":12705,"date":"2026-05-08T10:03:37","date_gmt":"2026-05-08T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/08\/new-ivanti-epmm-0-day-vulnerability-actively-exploited-in-attacks\/"},"modified":"2026-05-08T10:03:37","modified_gmt":"2026-05-08T10:03:37","slug":"new-ivanti-epmm-0-day-vulnerability-actively-exploited-in-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/08\/new-ivanti-epmm-0-day-vulnerability-actively-exploited-in-attacks\/","title":{"rendered":"New Ivanti EPMM 0-Day Vulnerability Actively Exploited in Attacks"},"content":{"rendered":"<p>    New Ivanti EPMM 0-Day Vulnerability Actively Exploited in Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Ivanti has issued a critical security advisory for its Endpoint Manager Mobile (EPMM) product, disclosing multiple actively exploited vulnerabilities, including CVE-2026-6973, and urging all on-premises EPMM customers to apply patches immediately.<\/p>\n<p>At the time of disclosure, Ivanti confirmed active exploitation of CVE-2026-6973, a vulnerability that requires admin authentication to succeed.<\/p>\n<p>The flaws exclusively affect the on-premises EPMM product and are not present in Ivanti Neurons for MDM, Ivanti\u2019s cloud-based unified endpoint management solution, Ivanti EPM, Ivanti Sentry, or any other Ivanti products.<\/p>\n<p>Exploitation activity has been described as \u201cvery limited\u201d at the time of public disclosure, though the company strongly warned that advanced AI models have dramatically collapsed the time-to-exploit window from days to mere hours after a vulnerability becomes public.<\/p>\n<p>In a notable shift in <a href=\"https:\/\/cybersecuritynews.com\/cybersecurity-risk-management-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerability management<\/a> strategy, Ivanti disclosed that it has integrated multiple advanced large language model (LLM) AI systems into its product security and engineering red team processes.<\/p>\n<p>This integration has enhanced the capabilities of its internal security teams to identify and remediate vulnerabilities that traditional static analysis (SAST) and dynamic analysis (DAST) tools typically miss.<\/p>\n<p><a href=\"https:\/\/hub.ivanti.com\/s\/article\/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Ivanti acknowledged<\/a> that some of the vulnerabilities being disclosed today were discovered directly through this AI-assisted process. The company maintains a \u201chuman in the loop\u201d policy to verify all automated or agentic findings, ensuring responsible use of AI in its security program.<\/p>\n<p>Ivanti\u2019s EPMM has been a recurring target for sophisticated threat actors. <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-6973\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CISA has flagged<\/a> at least 31 Ivanti defects on its Known Exploited Vulnerabilities (KEV) catalog since late 2021, and at least 19 defects across Ivanti products have been exploited in the past two years alone.<\/p>\n<p>Previous zero-day campaigns against EPMM include <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploiting-ivanti-endpoint-manager-mobile-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-4427<\/a> and <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploiting-ivanti-endpoint-manager-mobile-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-4428<\/a> in May 2025, and <a href=\"https:\/\/cybersecuritynews.com\/ivanti-mobileiron-api-access-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-35078<\/a> and <a href=\"https:\/\/cybersecuritynews.com\/chinese-state-sponsored-hackers-attacking-telecommunications\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-35082<\/a> in 2023, with some attacks attributed to Chinese state-sponsored threat groups.<\/p>\n<p>The consistent targeting of EPMM underscores the product\u2019s high-value position in enterprise mobile device management infrastructure.<\/p>\n<p>The vulnerabilities disclosed in <a href=\"https:\/\/hub.ivanti.com\/s\/article\/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Ivanti\u2019s May 2026 security advisory<\/a> affect only on-premises EPMM deployments. Organizations running cloud-based Ivanti Neurons for MDM are not impacted.<\/p>\n<p>Ivanti has published detailed remediation instructions through its official Security Advisory, with patch packages that the company says take only seconds to apply and cause no downtime.<\/p>\n<h2 class=\"wp-block-heading\" id=\"mitigation-and-recommended-actions\"><strong>Mitigations<\/strong><\/h2>\n<p>Ivanti strongly urges all on-premises EPMM administrators to take immediate action:<\/p>\n<ul class=\"wp-block-list\">\n<li>Apply the available security patch to all EPMM on-premises instances without delay<\/li>\n<li>Monitor Apache access logs at <code>\/var\/log\/httpd\/https-access_log<\/code> for signs of attempted or successful exploitation.<\/li>\n<li>Implement network segmentation to restrict EPMM administrative interfaces to trusted networks only.<\/li>\n<li>Review and harden mobile device management policies to reduce the overall attack surface<\/li>\n<li>Subscribe to Ivanti\u2019s Security Blog and the Ivanti Innovators Hub for real-time vulnerability alerts<\/li>\n<\/ul>\n<p>Ivanti cautioned that as AI-driven tooling becomes further embedded in its security processes, customers should expect an increase in vulnerability disclosures, a transparency initiative the company frames as a proactive step toward more resilient products rather than a sign of weakening security posture.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Cybercriminals now enter through your suppliers instead of your front door \u2013 <a href=\"https:\/\/www.manageengine.com\/products\/desktop-central\/webinars\/uk-cybersecurity-essentials-2026.html?utm_source=CSN&amp;utm_medium=TPS-mailer&amp;utm_campaign=UKCSW\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Free Webinar<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/ivanti-epmm-0-day-exploited\/\">New Ivanti EPMM 0-Day Vulnerability Actively Exploited in Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/ivanti-epmm-0-day-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Ivanti EPMM 0-Day Vulnerability Actively Exploited in Attacks Ivanti has issued a critical security advisory for its Endpoint Manager Mobile (EPMM) product, disclosing multiple actively exploited vulnerabilities, including CVE-2026-6973, and urging all on-premises EPMM customers to apply patches immediately. At the time of disclosure, Ivanti confirmed active exploitation of CVE-2026-6973, a vulnerability that requires [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-12705","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12705"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12705"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12705\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}