HIGH CISA KEV

CVE-2026-6973

CVSS v3

7.2

HIGH

EPSS Score

5.0%

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

CISA Known Exploited Vulnerability

Date Added
5/7/2026
Patch Due Date
5/10/2026
Ransomware Use
Unknown

Technical details

Published
5/7/2026

Frequently asked questions

What is CVE-2026-6973?

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

Is CVE-2026-6973 actively exploited?

Yes. CVE-2026-6973 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 5/10/2026.

What is the CVSS score for CVE-2026-6973?

CVE-2026-6973 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2026-6973 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.