ClosedMedium impactAI Generated

CISA Mandates Federal Patch of Ivanti EPMM Zero-Day CVE-2026-6973 by 10 May 2026

Occurred 7 May 2026ยทDetected 10 May 2026ยท
๐Ÿ‡บ๐Ÿ‡ธ United States federal agencies and globally exposed Ivanti EPMM on-premises deployments; CISA headquartered in Washington D.C., USA2 reportsEnded 29 May 2026
CyberPropertyCyberCasualty & Liability

CISA has added CVE-2026-6973, a high-severity remote code execution vulnerability in Ivanti Endpoint Manager Mobile (EPMM) versions 12.8.0.0 and earlier, to its Known Exploited Vulnerabilities catalogue following confirmed zero-day exploitation. The agency has ordered US federal agencies to apply patches by midnight 10 May 2026. Ivanti has released fixed versions (12.6.1.1, 12.7.0.1, 12.8.0.1) and confirmed exploitation is currently limited, requiring admin authentication. Over 800 Ivanti EPMM appliances remain exposed online according to Shadowserver, with the vulnerability affecting only on-premises deployments.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Medium impact. The vulnerability targets US federal agencies and over 800 internet-exposed on-premises EPMM appliances globally, posing significant risk to government and enterprise IT infrastructure. However, exploitation requires admin authentication and has so far been confirmed as very limited, constraining immediate insured loss potential.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Geographic Zone Matches

1 active match

  • TRIA Certified Areas
    Rule-basedConfidence 100%

Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.

Affected countries

๐Ÿ‡ช๐Ÿ‡บ European Union member states๐Ÿ‡บ๐Ÿ‡ธ United States

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts