• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

Ivanti EPMM CVE-2026-6973 RCE Beneath Energetic Exploitation Grants Admin-Stage Entry

Admin by Admin
May 8, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananCould 07, 2026Vulnerability / Community Safety

Ivanti is warning {that a} new safety flaw impacting Endpoint Supervisor Cell (EPMM) has been explored in restricted assaults within the wild.

The high-severity vulnerability, CVE-2026-6973 (CVSS rating: 7.2), is a case of improper enter validation affecting EPMM earlier than variations 12.6.1.1, 12.7.0.1, and 12.8.0.1.

It permits “a remotely authenticated consumer with administrative entry to attain distant code execution,” Ivanti stated in an advisory launched as we speak.

“We’re conscious of a really restricted variety of prospects exploited with CVE-2026-6973. Profitable exploitation requires Admin authentication. If prospects adopted Ivanti’s advice in January to rotate credentials when you have been exploited with CVE-2026-1281 and CVE-2026-1340, then your danger of exploitation from CVE-2026-6973 is considerably diminished.”

It is at the moment not recognized who’s behind the exploitation efforts, if any of these assaults have been profitable, and what the top targets of the assaults have been.

The event has prompted the U.S. Cybersecurity and Infrastructure Safety Company (CISA) to add the flaw to its Recognized Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Government Department (FCEB) companies to use the fixes by Could 10, 2026.

Additionally patched by Ivanti in EPMM are 4 different flaws –

  • CVE-2026-5786 (CVSS rating: 8.8) – An improper entry management vulnerability that permits a distant authenticated attacker to realize administrative entry.
  • CVE-2026-5787 (CVSS rating: 8.9) – An improper certificates validation vulnerability that permits a distant unauthenticated attacker to impersonate registered Sentry hosts and procure legitimate CA-signed consumer certificates.
  • CVE-2026-5788 (CVSS rating: 7.0) – An improper entry management vulnerability that permits a distant unauthenticated attacker to invoke arbitrary strategies.
  • CVE-2026-7821 (CVSS rating: 7.4) – An improper certificates validation vulnerability that permits a distant unauthenticated attacker to enroll a tool belonging to a restricted set of unenrolled gadgets, resulting in data disclosure in regards to the EPMM equipment and impacting the integrity of the newly enrolled machine id.

“The problems solely have an effect on the on-prem EPMM product, and are usually not current in Ivanti Neurons for MDM, Ivanti’s cloud-based unified endpoint administration answer, Ivanti EPM (a equally named, however totally different product), Ivanti Sentry, or some other Ivanti merchandise,” the corporate stated.

Tags: AccessActiveAdminLevelCVE20266973EPMMExploitationGrantsIvantiRCE
Admin

Admin

Next Post
Andy Serkis Says Hollywood’s ‘Snobbery’ In direction of Video Sport is Altering

Andy Serkis Says Hollywood's 'Snobbery' In direction of Video Sport is Altering

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

From Design-First to Movement-Pushed: Dylan Brouwer’s Journey into the No-Code Frontier

From Design-First to Movement-Pushed: Dylan Brouwer’s Journey into the No-Code Frontier

January 22, 2026
That is quantity 10,000 | Seth’s Weblog

Operator error | Seth’s Weblog

July 4, 2026

Trending.

Backrooms director Kane Parsons explains the birds, the portals, and his sensible results

Backrooms director Kane Parsons explains the birds, the portals, and his sensible results

May 31, 2026
Telegram ban in India sparks a rush to VPNs, rival apps

Telegram ban in India sparks a rush to VPNs, rival apps

June 19, 2026
The Full Information to EcoGPT

The Full Information to EcoGPT

June 6, 2026
100 Most Costly Key phrases for Google Advertisements in 2026

100 Most Costly Key phrases for Google Advertisements in 2026

January 13, 2026
Authorized DUI PPC Companies in Atlanta

Authorized DUI PPC Companies in Atlanta

June 14, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Knowledge to Attackers

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Knowledge to Attackers

August 9, 2026
8 Greatest Video games to Stroll and Speak With Your Pals

8 Greatest Video games to Stroll and Speak With Your Pals

August 9, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved