DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:03:37ZSOURCES: 14CRITICAL: 15
⚠ ACTIVE ALERTS
SYLVANITE CRITICAL — SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated… /// @MsftSecIntel CRITICAL — We are tracking TeamPCP (UNC6780) activity following the GitHub internal repository… /// @GossiTheDog CRITICAL — The GitHub / TeamPCP breach is now being monetized on BreachForums. Listing is up — $95k… /// @struppigel CRITICAL — SUPPLY CHAIN ALERT: Laravel-Lang PHP packages backdoored May 22-23 via hijacked GitHub… /// @MalwareHunterTeam CRITICAL — Seeing fresh DebugElevator stealer log batches already appearing for sale on Exploit.in —…
15Critical Threats
8Active CVEs
0IOCs Tracked
0New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-6973PUBLISHED: 2026-05-07
HIGHCVE-2026-6973★ CISA KEV LISTED

Ivanti EPMM Authenticated Admin RCE Exploited as Zero-Day (CISA KEV)

VENDOR: Ivanti//PRODUCT: Endpoint Manager Mobile (EPMM) — on-premises
7.2
HIGH
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
LIMITED EXPLOITATION

An improper input validation vulnerability in Ivanti EPMM allows a remotely authenticated attacker with administrative privileges to execute arbitrary code on the underlying appliance. Ivanti and the Belgian Centre for Cyber Security confirmed active zero-day exploitation against a limited number of customers; threat actors are assessed to be chaining this with stolen admin credentials harvested from the January 2026 EPMM zero-days (CVE-2026-1281/1340, CVSS 9.8). This is the third confirmed EPMM zero-day exploitation event in 2026; prior campaigns have been linked to China and Iran-nexus actors. Over 800 internet-exposed EPMM instances tracked by Shadowserver. CISA added to KEV May 7, 2026, with a 3-day federal remediation window.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
HIGH
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSIvanti EPMM versions 12.8.0.0 and prior; fixed in 12.6.1.1, 12.7.0.1, 12.8.0.1
  • Ivanti Security Advisory: https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs
  • CISA KEV / Alert: https://www.cisa.gov/news-events/alerts/2026/05/07/cisa-adds-one-known-exploited-vulnerability-catalog
  • Security Boulevard: https://securityboulevard.com/2026/05/ivanti-warns-of-new-epmm-flaw-exploited-in-zero-day-attacks/
  • The Hacker News: https://thehackernews.com/2026/05/ivanti-epmm-cve-2026-6973-rce-under.html
  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6973
SHARE BRIEF:✕ Post on Xin Share on LinkedIn