Consumer Alerts Tracker
CISA KEV

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

Official details

Category
Known exploited vulnerability
Classification
Ransomware use: Unknown
Company or vendor
Ivanti Endpoint Manager Mobile (EPMM)
Affected product
Endpoint Manager Mobile (EPMM)
Risk or reason
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
Remedy or action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Official ID
CVE-2026-6973