CVE-2026-6973 – Ivanti Endpoint Manager Mobile

CVSS 7.2 IMPORTANT

“An actively exploited mobile management gap can turn every managed device into a target.”

This patch addresses CVE-2026-6973 in Ivanti Endpoint Manager Mobile, a High severity vulnerability that can allow unauthorized access or control within managed environments. The CVSS score is 7.2, which is High severity. The update improves authentication controls and closes a gap that could be abused to bypass security boundaries in enterprise mobility deployments.

Active exploitation has been confirmed, increasing the urgency for organizations using this platform. Attackers can leverage this weakness to gain footholds across managed devices, potentially impacting enterprise data and device integrity at scale.

Key Details

Affected Product
Ivanti Endpoint Manager Mobile
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-20
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.