Skip to content
Briefings are running a touch slower this week while we rebuild the foundations.See roadmap
Cybersecurity: Threats and Defences
17APR

Ivanti EPMM logs fourth KEV zero-day since 2023

3 min read
13:56UTC

CISA added CVE-2026-6973 in Ivanti Endpoint Manager Mobile to KEV on 7 May, the fourth zero-day in the same on-premises MDM product to reach the federal catalogue since 2023. Ivanti confirms limited exploitation; on-premises deployments are affected, Ivanti Neurons cloud is not.

TechnologyDeveloping
Key takeaway

Four Ivanti MDM zero-days in three years: state actors have made the mobile-device-management plane a sustained primary target.

CISA added CVE-2026-6973 in Ivanti Endpoint Manager Mobile (EPMM), Ivanti's on-premises mobile device manager, to the Known Exploited Vulnerabilities (KEV) catalogue on 7 May with a 10 May federal deadline.1 The CVSS score is 7.2. The vulnerability allows a remotely authenticated administrator to achieve Remote Code Execution; Ivanti confirms limited exploitation in the wild and notes that customers who rotated credentials after the January 2026 zero-days on the same product carry reduced risk.2 The on-premises deployment is affected; Ivanti Neurons for MDM in the cloud is not.

MDM (Mobile Device Management) servers occupy a privileged position in enterprise networks: they govern every staff phone and laptop in a managed estate. An attacker with administrative access to the MDM server controls every device it manages, with no further exploitation required. The Norwegian Security and Service Organisation and US government agencies were victims of the prior three Ivanti EPMM zero-days. Reaching the fourth in three years with the same product confirms sustained attention from state-aligned actors on the on-premises MDM plane specifically.

The comparison with the Stryker incident clarifies the symmetry. Stryker showed how a single stolen Microsoft Intune credential could trigger a device wipe across 200,000 endpoints in 79 countries and produce a US Securities and Exchange Commission (SEC) 8-K/A materiality filing. CVE-2026-6973 extends the pressure to the on-premises side in the same quarter: cloud MDM under criminal credential abuse, on-premises MDM under state-actor software exploitation, simultaneously. For UK and EU public-sector estates running on-premises Ivanti EPMM (including NHS trusts), credential rotation after each new zero-day is now a permanent operational cadence, not a one-off remediation task.

Deep Analysis

In plain English

Ivanti makes software that large organisations use to manage thousands of smartphones, tablets, and laptops. With this software, IT departments can remotely lock a stolen phone, push a security update to every device at once, or wipe a device if it is lost. That level of control makes the software itself a high-value target. This is the fourth serious security flaw in the same Ivanti product since 2023 to be listed on the US government's priority patch list. Each time a flaw appears, organisations that have not patched can have their management software taken over, which gives attackers control over every device that software manages. The NHS in the UK uses this product across multiple hospitals. So does the Norwegian government, which was attacked through an earlier version of the same flaw.

Deep Analysis
Root Causes

Ivanti EPMM's on-premises deployment model requires a single server to handle device enrolment, policy distribution, and remote wipe commands with administrator-level authority. That single-server architecture means the management plane's authentication layer is both the attack surface and the defence. A remotely-authenticated administrator RCE (CVSS 7.2) means an attacker who has obtained any valid admin credential can achieve code execution on the server controlling all managed devices.

The 'limited exploitation' caveat from Ivanti reflects the higher bar for this CVE versus prior ones: CVE-2026-6973 requires a valid admin credential, whereas earlier Ivanti EPMM zero-days allowed unauthenticated access. This means the credential-rotation guidance Ivanti issued after January 2026 zero-days does provide some protection, but organisations that did not rotate credentials remain fully exposed.

The Norwegian Security and Service Organisation's prior victimisation by an earlier Ivanti EPMM zero-day is publicly documented, which means state actors have confirmed the management plane provides access to government device fleets with high value.

What could happen next?
  • Risk

    Organisations running on-premises Ivanti EPMM without credential rotation after January 2026 are fully exposed to CVE-2026-6973 and should treat their device fleet as potentially under attacker policy control until the patch is applied and credentials rotated.

    Immediate · 0.9
  • Consequence

    Four Ivanti EPMM zero-days in three years will accelerate public-sector migration planning towards cloud-MDM alternatives, with NHS Digital and Nordic government bodies likely to produce business cases for migration in the next procurement cycle.

    Medium term · 0.7
  • Risk

    State-aligned actors have confirmed MDM servers as a primary target. Organisations that manage sensitive devices (law enforcement, intelligence, healthcare) and run on-premises MDM now face sustained threat-actor interest regardless of which vendor they use.

    Long term · 0.85
First Reported In

Update #3 · CISA's deadline outruns Palo Alto's patch

CISA· 8 May 2026
Read original
Different Perspectives
Google Threat Intelligence Group
Google Threat Intelligence Group
GTIG's attribution of the GitHub breach extends UNC6780's documented arc from SAP npm through Cisco AI Defense to GitHub's own estate; its 36-hour LiteLLM exploitation set the speed benchmark CISA AA26-148A is designed to address. GTIG's published tracking gives defenders the actor profile needed to assess their own developer-toolchain exposure.
Enterprise security buyers / CISO community
Enterprise security buyers / CISO community
For enterprise security leaders, two KEV AI-orchestration entries in three weeks (LiteLLM 8 May, Langflow 21 May) convert shadow AI tooling from a governance risk to a confirmed attack surface requiring immediate software asset inventory. The 65 per cent gap in enterprise AI tool inventories documented by Wiz Research is now a liability rather than a compliance footnote.
DSIT / UK Government
DSIT / UK Government
DSIT framed the £14.7 billion sector figure and the Cyber Resilience Pledge as a paired signal: commercial strength alongside supply-chain accountability, with £90 million targeting the NHS supplier exposure this briefing's threat events directly illustrate. The voluntary Pledge's enforceability gap, prior to the Cyber Security and Resilience Bill reaching Royal Assent, is the question its launch does not answer.
GitHub / Microsoft
GitHub / Microsoft
GitHub confirmed that no customer repositories or user data were affected by the Nx Console breach, but acknowledged approximately 3,800 internal repositories were cloned and referred to CISA Alert AA26-148A's allow-listing guidance. The incident puts Microsoft in the position of operating a marketplace whose publisher-verification gap is now a documented attack vector in a federal advisory.
Tsinghua University Institute for International Strategic Studies
Tsinghua University Institute for International Strategic Studies
Beijing-aligned commentary rejects US attribution of PRC-nexus clusters (UNC2814, APT45, UAT-8616) as politically motivated framing, characterising the April sixteen-agency joint advisory as coordinated Western pressure rather than independent technical assessment.
Cisco
Cisco
Cisco has not confirmed the UNC6780 breach scope beyond the named AI Defense and AI Assistant projects; GitHub confirmed an investigation. CVE-2026-20182 is the sixth Cisco SD-WAN KEV entry in 2026, reaching that milestone the same week UNC6780's source-code visibility into the portfolio became public.