• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

Ivanti EPMM CVE-2026-6973 RCE Beneath Energetic Exploitation Grants Admin-Stage Entry

Admin by Admin
May 8, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananCould 07, 2026Vulnerability / Community Safety

Ivanti is warning {that a} new safety flaw impacting Endpoint Supervisor Cell (EPMM) has been explored in restricted assaults within the wild.

The high-severity vulnerability, CVE-2026-6973 (CVSS rating: 7.2), is a case of improper enter validation affecting EPMM earlier than variations 12.6.1.1, 12.7.0.1, and 12.8.0.1.

It permits “a remotely authenticated consumer with administrative entry to attain distant code execution,” Ivanti stated in an advisory launched as we speak.

“We’re conscious of a really restricted variety of prospects exploited with CVE-2026-6973. Profitable exploitation requires Admin authentication. If prospects adopted Ivanti’s advice in January to rotate credentials when you have been exploited with CVE-2026-1281 and CVE-2026-1340, then your danger of exploitation from CVE-2026-6973 is considerably diminished.”

It is at the moment not recognized who’s behind the exploitation efforts, if any of these assaults have been profitable, and what the top targets of the assaults have been.

The event has prompted the U.S. Cybersecurity and Infrastructure Safety Company (CISA) to add the flaw to its Recognized Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Government Department (FCEB) companies to use the fixes by Could 10, 2026.

Additionally patched by Ivanti in EPMM are 4 different flaws –

  • CVE-2026-5786 (CVSS rating: 8.8) – An improper entry management vulnerability that permits a distant authenticated attacker to realize administrative entry.
  • CVE-2026-5787 (CVSS rating: 8.9) – An improper certificates validation vulnerability that permits a distant unauthenticated attacker to impersonate registered Sentry hosts and procure legitimate CA-signed consumer certificates.
  • CVE-2026-5788 (CVSS rating: 7.0) – An improper entry management vulnerability that permits a distant unauthenticated attacker to invoke arbitrary strategies.
  • CVE-2026-7821 (CVSS rating: 7.4) – An improper certificates validation vulnerability that permits a distant unauthenticated attacker to enroll a tool belonging to a restricted set of unenrolled gadgets, resulting in data disclosure in regards to the EPMM equipment and impacting the integrity of the newly enrolled machine id.

“The problems solely have an effect on the on-prem EPMM product, and are usually not current in Ivanti Neurons for MDM, Ivanti’s cloud-based unified endpoint administration answer, Ivanti EPM (a equally named, however totally different product), Ivanti Sentry, or some other Ivanti merchandise,” the corporate stated.

Tags: AccessActiveAdminLevelCVE20266973EPMMExploitationGrantsIvantiRCE
Admin

Admin

Next Post
Andy Serkis Says Hollywood’s ‘Snobbery’ In direction of Video Sport is Altering

Andy Serkis Says Hollywood's 'Snobbery' In direction of Video Sport is Altering

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

If Your Youngsters Out of the blue Need To Play Star Fox, Right here's How

If Your Youngsters Out of the blue Need To Play Star Fox, Right here's How

April 3, 2026
Instruments and the lengthy tail

Maybe we now have what we’d like

November 9, 2025

Trending.

AI & data-driven Starbucks – Deep Brew

AI & data-driven Starbucks – Deep Brew

May 18, 2026
Attackers Exploit MCP RCE, Blind Immediate Injection and Reminiscence Credential Theft Towards AI Infrastructure

Attackers Exploit MCP RCE, Blind Immediate Injection and Reminiscence Credential Theft Towards AI Infrastructure

August 29, 2026
The Full Information to EcoGPT

The Full Information to EcoGPT

June 6, 2026
Hasbro Information Breach Uncovered Worker Private Data

Hasbro Information Breach Uncovered Worker Private Data

August 30, 2026
High LLM Observability and Analysis Platforms in 2026: Langfuse, LangSmith, Braintrust, Arize, and Extra In contrast

High LLM Observability and Analysis Platforms in 2026: Langfuse, LangSmith, Braintrust, Arize, and Extra In contrast

August 9, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

AEO checker instruments that measure reply engine visibility [2026]

AEO checker instruments that measure reply engine visibility [2026]

September 24, 2026
Qualcomm’s new chips present how AI brokers are tying collectively telephones, laptops, and earbuds

Qualcomm’s new chips present how AI brokers are tying collectively telephones, laptops, and earbuds

September 24, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved