Junglewise Threat Intelligence

CVE-2026-6973: Ivanti Endpoint Manager Mobile RCE via Apache directive injection

CVE-2026-6973 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2026-05-07

Technologies: Ivanti Endpoint Manager Mobile (EPMM), Ivanti Endpoint Manager Mobile, Ivanti MobileIron Core. Vendors: Ivanti.

Executive brief

Ivanti Endpoint Manager Mobile (EPMM) is a platform used by organizations to manage and secure mobile devices. A security vulnerability has been identified that allows an attacker with administrative credentials to take full control of the server. This could lead to the theft of sensitive mobile device data, unauthorized access to the corporate network, or a complete shutdown of mobile management services.

Technical details

A configuration control vulnerability (CWE-15) exists in Ivanti Endpoint Manager Mobile (EPMM) due to improper input validation. A remote attacker with administrative privileges can inject arbitrary Apache directives into the system configuration. This injection allows the attacker to achieve remote code execution (RCE) on the underlying operating system. The vulnerability affects versions prior to 12.9.0.1, 12.8.0.3, and 12.7.0.2. Although it requires high privileges (PR:H), it has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.

Affected products

  • Ivanti Endpoint Manager Mobile (EPMM) before 12.9.0.1, 12.8.0.3, and 12.7.0.2

Timeline

  • 2026-05-07: disclosed
  • 2026-05-07: advisory
  • 2026-05-07: kev added: Added to CISA KEV catalog on the same day as publication.
  • 2026-06-09: other: NVD record updated with refined version and CWE information.

References

Related threats