ctipilot.chSwitzerland · Europe · Public sector

Ivanti EPMM on-prem — admin API improper input validation → RCE (CVSS 7.2, ITW, KEV deadline 2026-05-10)

cve · CVE-2026-6973

Story timeline

  1. 2026-05-08CTI Daily Brief — 2026-05-08
    immediate-actionsFirst coverage. CWE-20; chained with CVE-2026-5787 for fully pre-auth RCE. CISA KEV deadline 2026-05-10. ~508 EU internet-reachable on-prem instances. Fixed in 12.6.1.1/12.7.0.1/12.8.0.1. Deep dive § 7.