Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

Ivanti EPMM logs fourth KEV zero-day since 2023

3 min read
16:08UTC

CISA added CVE-2026-6973 in Ivanti Endpoint Manager Mobile to KEV on 7 May, the fourth zero-day in the same on-premises MDM product to reach the federal catalogue since 2023. Ivanti confirms limited exploitation; on-premises deployments are affected, Ivanti Neurons cloud is not.

TechnologyDeveloping
Key takeaway

Four Ivanti MDM zero-days in three years: state actors have made the mobile-device-management plane a sustained primary target.

CISA added CVE-2026-6973 in Ivanti Endpoint Manager Mobile (EPMM), Ivanti's on-premises mobile device manager, to the Known Exploited Vulnerabilities (KEV) catalogue on 7 May with a 10 May federal deadline.1 The CVSS score is 7.2. The vulnerability allows a remotely authenticated administrator to achieve remote code execution; Ivanti confirms limited exploitation in the wild and notes that customers who rotated credentials after the January 2026 zero-days on the same product carry reduced risk.2 The on-premises deployment is affected; Ivanti Neurons for MDM in the cloud is not.

MDM (Mobile Device Management) servers occupy a privileged position in enterprise networks: they govern every staff phone and laptop in a managed estate. An attacker with administrative access to the MDM server controls every device it manages, with no further exploitation required. The Norwegian Security and Service Organisation and US government agencies were victims of the prior three Ivanti EPMM zero-days. Reaching the fourth in three years with the same product confirms sustained attention from state-aligned actors on the on-premises MDM plane specifically.

The comparison with the Stryker incident clarifies the symmetry. Stryker showed how a single stolen Microsoft Intune credential could trigger a device wipe across 200,000 endpoints in 79 countries and produce a US Securities and Exchange Commission (SEC) 8-K/A materiality filing. CVE-2026-6973 extends the pressure to the on-premises side in the same quarter: cloud MDM under criminal credential abuse, on-premises MDM under state-actor software exploitation, simultaneously. For UK and EU public-sector estates running on-premises Ivanti EPMM (including NHS trusts), credential rotation after each new zero-day is now a permanent operational cadence, not a one-off remediation task.

Deep Analysis

In plain English

Ivanti makes software that large organisations use to manage thousands of smartphones, tablets, and laptops. With this software, IT departments can remotely lock a stolen phone, push a security update to every device at once, or wipe a device if it is lost. That level of control makes the software itself a high-value target. This is the fourth serious security flaw in the same Ivanti product since 2023 to be listed on the US government's priority patch list. Each time a flaw appears, organisations that have not patched can have their management software taken over, which gives attackers control over every device that software manages. The NHS in the UK uses this product across multiple hospitals. So does the Norwegian government, which was attacked through an earlier version of the same flaw.

Deep Analysis
Root Causes

Ivanti EPMM's on-premises deployment model requires a single server to handle device enrolment, policy distribution, and remote wipe commands with administrator-level authority. That single-server architecture means the management plane's authentication layer is both the attack surface and the defence. A remotely-authenticated administrator RCE (CVSS 7.2) means an attacker who has obtained any valid admin credential can achieve code execution on the server controlling all managed devices.

The 'limited exploitation' caveat from Ivanti reflects the higher bar for this CVE versus prior ones: CVE-2026-6973 requires a valid admin credential, whereas earlier Ivanti EPMM zero-days allowed unauthenticated access. This means the credential-rotation guidance Ivanti issued after January 2026 zero-days does provide some protection, but organisations that did not rotate credentials remain fully exposed.

The Norwegian Security and Service Organisation's prior victimisation by an earlier Ivanti EPMM zero-day is publicly documented, which means state actors have confirmed the management plane provides access to government device fleets with high value.

What could happen next?
  • Risk

    Organisations running on-premises Ivanti EPMM without credential rotation after January 2026 are fully exposed to CVE-2026-6973 and should treat their device fleet as potentially under attacker policy control until the patch is applied and credentials rotated.

    Immediate · 0.9
  • Consequence

    Four Ivanti EPMM zero-days in three years will accelerate public-sector migration planning towards cloud-MDM alternatives, with NHS Digital and Nordic government bodies likely to produce business cases for migration in the next procurement cycle.

    Medium term · 0.7
  • Risk

    State-aligned actors have confirmed MDM servers as a primary target. Organisations that manage sensitive devices (law enforcement, intelligence, healthcare) and run on-premises MDM now face sustained threat-actor interest regardless of which vendor they use.

    Long term · 0.85
First Reported In

Update #3 · CISA's deadline outruns Palo Alto's patch

CISA· 8 May 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.