CVE-2026-7821Disclosure(ivanti / endpoint_manager_mobile)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch ivanti endpoint_manager_mobile systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager_mobile

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-08); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
endpoint_manager_mobile

2 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-07: 1Mentions · 2026-05-08: 2Mentions · 2026-06-07: 1Mentions · 2026-06-12: 1Active Exploitation · 2026-05-08: 1Patch / Workaround · 2026-05-08: 2Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 2Technical Details · 2026-06-12: 105-0705-0806-0706-12
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-071
Disclosure1
2026-05-082
Patch2
2026-06-071
Disclosure1
2026-06-121
General1
Full discourse5 posts
  • Cytex@cytexsmb
    Patch

    🚨 Ivanti EPMM Zero-Day Under Attack Ivanti has disclosed a new security vulnerability in Endpoint Manager Mobile that is being exploited in limited attacks. The flaw, tracked as CVE-2026-6973 with a CVSS score of 7.2, allows a remotely authenticated user with administrative access to execute code on the system. Successful exploitation requires valid admin credentials, meaning attackers must already have access before using this flaw. The Vulnerability 🔴 CVE-2026-6973 – CVSS 7.2. Improper input validation in EPMM versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1. Remote authenticated user with admin access can achieve remote code execution. Attacker must already have administrative credentials. 📜 Critical Context Ivanti recommended in January that customers rotate credentials if they were exploited with CVE-2026-1281 and CVE-2026-1340. Organizations that followed that guidance have significantly reduced risk. The attacker needs admin access; credential rotation blocks the prerequisite. Exploitation Status Limited attacks observed in the wild. Unknown who is behind the exploitation. Unknown end goals of the attacks. US CISA Action Added to Known Exploited Vulnerabilities catalog. Federal agencies must apply fixes by May 10, 2026. 🩹 Additional Patched Flaws CVE-2026-5786 (CVSS 8.8): Improper access control allowing remote authenticated attacker to gain admin access. CVE-2026-5787 (CVSS 8.9): Improper certificate validation allowing unauthenticated attacker to impersonate Sentry hosts and obtain valid CA-signed client certificates. CVE-2026-5788 (CVSS 7.0): Improper access control allowing unauthenticated attacker to invoke arbitrary methods. CVE-2026-7821 (CVSS 7.4): Improper certificate validation allowing unauthenticated attacker to enroll restricted devices, leading to information disclosure. 🛡️ Mitigations Apply available security patches to all EPMM on-premises instances immediately. Monitor Apache access logs for signs of attempted or successful exploitation. Implement network segmentation to restrict EPMM administrative interfaces to trusted networks only. Review and harden mobile device management policies. This RCE requires admin privileges. The January credential rotation advice directly reduces exposure. Organizations that did not rotate credentials remain at higher risk.

    Post summary

    A newly disclosed CVE‑2026‑6973 vulnerability in Ivanti Endpoint Manager Mobile allows remote code execution with admin credentials and is being exploited in limited attacks; patches and credential rotation are advised.

    12130140
    851 followersView on X
  • Cytex@cytexsmb
    Patch

    Ivanti CVE-2026-6973 is an RCE flaw, but it requires administrative access to exploit. The attacker must already have valid admin credentials before they can use this vulnerability. That means credential theft or prior compromise is a prerequisite, not an outcome of this bug. What the vulnerability actually does: Allows a remote authenticated user with admin access to execute code on the EPMM server. Improper input validation leads to remote code execution. Affects EPMM versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1. Why credential rotation matters more than patching in this case: Ivanti advised customers in January to rotate credentials if they were exploited with two earlier CVEs (CVE-2026-1281 and CVE-2026-1340). Organizations that rotated credentials have significantly reduced risk for the new flaw: CVE-2026-6973. Without valid admin credentials, an attacker cannot use this RCE. CISA added to KEV. Federal agencies must patch by May 10, 2026. Four additional vulnerabilities were fixed alongside this RCE: CVE-2026-5786 (CVSS 8.8): Authenticated attacker gains admin access. CVE-2026-5787 (CVSS 8.9): Unauthenticated attacker impersonates Sentry hosts and obtains valid certificates. CVE-2026-5788 (CVSS 7.0): Unauthenticated attacker invokes arbitrary methods. CVE-2026-7821 (CVSS 7.4): Unauthenticated attacker enrolls restricted devices leading to information disclosure. The pattern: Two of the additional flaws (CVE-2026-5787 and CVE-2026-5788) are unauthenticated. An attacker could use those to gain initial access, then use CVE-2026-6973 to escalate to RCE. The chain is the real threat, not the individual vulnerability. As AI-driven tooling becomes more embedded in security processes, customers should expect an increase in vulnerability disclosures. The defensive priority: Patch all five vulnerabilities together. Rotate credentials if you have not done so since January. Assume that unauthenticated flaws (CVE-2026-5787 and CVE-2026-5788) may have been used to obtain the admin credentials required for CVE-2026-6973.

    Post summary

    The post emphasizes patching and credential rotation for CVE‑2026‑6973, outlines its technical specifics and related vulnerabilities, but provides neither PoC nor evidence of current exploitation.

    11010117
    840 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    8, 2026 — The Device Manager Is Compromised: Ivanti EPMM's Five-CVE Zero-Day Bundle and the January Credential Domino. Published: May 8, 2026 | Category: CVE Deep Dive | Severity: Critical CVEs: CVE-2026-6973 · CVE-2026-5786 · CVE-2026-5787 · CVE-2026-5788 · CVE-2026-7821

    Post summary

    A brief announcement of a 5‑CVE zero‑day bundle affecting Ivanti EPMM, labeled critical but lacking further technical or exploit specifics.

    1000036
    253 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-7821: Ivanti EPMM Certificate Validation Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04lcl9x0

    Post summary

    The brief title only identifies a certificate validation bug for Ivanti EPMM, but offers no evidence of exploitation, patches, or PoCs.

    0000025
    31 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-7821 Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthe… CVSS 7.4 Full analysis → https://sec.kaitan.id/cves/CVE-2026-7821 #Ivanti #CyberSecurity #InfoSec

    Post summary

    The text announces CVE‑2026‑7821, detailing improper certificate validation in specific Ivanti EPMM versions and its CVSS 7.4 score, but provides no PoC, exploit, active exploitation report, or patch information.

    0000041
    515 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager_mobile---
Appivantiendpoint_manager_mobile12.7.0.0--
Appivantiendpoint_manager_mobile12.8.0.0--

Explore more