CVE-2026-6973 – Ivanti Endpoint Manager Mobile
CVSS 7.2
IMPORTANT
“An actively exploited mobile management gap can turn every managed device into a target.”
This patch addresses CVE-2026-6973 in Ivanti Endpoint Manager Mobile, a High severity vulnerability that can allow unauthorized access or control within managed environments. The CVSS score is 7.2, which is High severity. The update improves authentication controls and closes a gap that could be abused to bypass security boundaries in enterprise mobility deployments.
Active exploitation has been confirmed, increasing the urgency for organizations using this platform. Attackers can leverage this weakness to gain footholds across managed devices, potentially impacting enterprise data and device integrity at scale.
Key Details
- Affected Product
- Ivanti Endpoint Manager Mobile
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- CWE Classification
- CWE-20
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.