IC Technology & Surveillance — 2026-05-08

CISA Adds Ivanti EPMM Zero-Day to Known Exploited Vulnerabilities Catalog

CISA on May 7 added CVE-2026-6973 to its Known Exploited Vulnerabilities catalog and set a May 10 remediation deadline for Federal Civilian Executive Branch agencies. Ivanti's advisory rated the flaw CVSS 7.2 and described it as enabling remote code execution by an authenticated attacker with administrative access on on-premises EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1. The company confirmed exploitation against "a very limited number of customers" and stated that organizations that rotated credentials following earlier EPMM compromises via CVE-2026-1281 and CVE-2026-1340 face reduced risk. The same advisory patched four additional EPMM flaws, the most severe being CVE-2026-5787 (CVSS 8.9), which Ivanti said permits unauthenticated impersonation of registered Sentry hosts to obtain valid CA-signed client certificates.

Analysis
CISA's three-day remediation window signals active exploitation already underway, and unpatched FCEB agencies are likely to face additional intrusion attempts before May 10. The authentication requirement for CVE-2026-6973 offers limited protection: actors who harvested credentials during prior EPMM compromises via CVE-2026-1281 and CVE-2026-1340 retain usable access. Co-disclosed CVE-2026-5787, unauthenticated, CVSS 8.9, corroborated across three outlets without independent technical verification, enables impersonation of Sentry hosts to obtain CA-signed client certificates, yielding persistence and lateral movement well beyond EPMM. Ivanti's "very limited number of customers" framing may instead reflect a concluded targeted operation, meaning broader exploitation before May 10 would remain constrained regardless of patch status.
4 sources
  1. CISA tags Ivanti EPMM flaw as actively exploited in attacks - BleepingComputer
  2. Known Exploited Vulnerabilities Catalog - CISA
  3. Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access - The Hacker News
  4. U.S. CISA adds a flaw in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalog - Security Affairs

View in full brief →

UNCLASSIFIED // OPEN SOURCE