<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/ivanti-patches-actively-exploited-epmm-zero-day-cisa-orders-federal-agencies-to-act-by-may-10-8fgitfgpz" -->

---
title: Ivanti patches actively exploited EPMM zero-day, CISA...
description: Ivanti has patched five high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) on-premises product, including one actively exploited zero-day...
canonical: https://daily.dev/posts/ivanti-patches-actively-exploited-epmm-zero-day-cisa-orders-federal-agencies-to-act-by-may-10-8fgitfgpz
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Ivanti patches actively exploited EPMM zero-day, CISA orders federal agencies to act by May 10 | daily.dev
og:description: Ivanti has patched five high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) on-premises product, including one actively exploited zero-day...
og:url: https://daily.dev/posts/ivanti-patches-actively-exploited-epmm-zero-day-cisa-orders-federal-agencies-to-act-by-may-10-8fgitfgpz
og:image: https://api.daily.dev/og/posts/8FGITFgpz.png
og:image:alt: Ivanti patches actively exploited EPMM zero-day, CISA orders federal agencies to act by May 10
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Ivanti patches actively exploited EPMM zero-day, CISA orders federal agencies to act by May 10

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Ivanti has patched five high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) on-premises product, including one actively exploited zero-day (CVE-2026-6973) that enables remote code execution via improper input validation. CISA has added the flaw to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch by May 10. Over 850 EPMM instances are internet-exposed. This is the third EPMM zero-day in recent months, bringing Ivanti's total CISA-flagged exploited vulnerabilities to 33. Patched versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 are available. Admins are advised to patch immediately, rotate credentials, and review account activity.

## Content

Ivanti has disclosed five new vulnerabilities in its Endpoint Manager Mobile (EPMM) on-premises product, one of which is already being exploited in the wild. CISA has added the actively exploited flaw to its Known Exploited Vulnerabilities Catalog and given federal agencies until May 10 to patch.

## The vulnerability

The exploited flaw, tracked as CVE-2026-6973, is a high-severity remote code execution bug caused by improper input validation. It affects EPMM 12.8.0.0 and all earlier on-premises versions. Exploitation requires admin authentication, though Ivanti notes that attackers may have obtained credentials through prior exploits targeting the same product.

Patched versions are available now: 12.6.1.1, 12.7.0.1, and 12.8.0.1.

Four additional high-severity EPMM vulnerabilities were patched in the same release. None of those have been observed exploited in the wild so far.

## Exposure and context

More than 850 EPMM instances are currently reachable from the internet, according to public scanning data. This is the third EPMM zero-day patched in recent months — two others were disclosed in January and also triggered CISA emergency directives. CISA has now flagged 33 Ivanti vulnerabilities as exploited in the wild in total, making this a recurring pattern rather than an isolated incident.

Ivanti says it has been using AI tools to proactively find vulnerabilities internally, which may explain an uptick in disclosures going forward.

## What to do

Ivanti and security researchers recommend:

- Patch to 12.6.1.1, 12.7.0.1, or 12.8.0.1 immediately
- Rotate admin credentials even if there are no signs of compromise
- Review admin account activity for anything unusual

For organizations still running legacy on-premises MDM, this is a reasonable moment to evaluate whether a move toward Zero Trust architectures makes sense. EPMM has now been a repeated target, and the attack surface isn't shrinking.

## Similar posts on daily.dev

- [CISA orders feds to patch exploited Ivanti EPMM flaw by Sunday](https://daily.dev/posts/cisa-orders-feds-to-patch-exploited-ivanti-epmm-flaw-by-sunday-q37rvz2h1) · BleepingComputer · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/ivanti-patches-actively-exploited-epmm-zero-day-cisa-orders-federal-agencies-to-act-by-may-10-8fgitfgpz)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Ivanti patches actively exploited EPMM zero-day, CISA orders federal agencies to act by May 10","url":"https://daily.dev/posts/ivanti-patches-actively-exploited-epmm-zero-day-cisa-orders-federal-agencies-to-act-by-may-10-8fgitfgpz","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/ivanti-patches-actively-exploited-epmm-zero-day-cisa-orders-federal-agencies-to-act-by-may-10-8fgitfgpz"},"datePublished":"2026-05-08T21:05:04.825Z","dateModified":"2026-05-08T21:05:48.149Z","description":"Ivanti has patched five high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) on-premises product, including one actively exploited zero-day...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0818993d9ee54b98c112633c67d8c0f8?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0818993d9ee54b98c112633c67d8c0f8?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/ivanti-patches-actively-exploited-epmm-zero-day-cisa-orders-federal-agencies-to-act-by-may-10-8fgitfgpz","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,zero-day","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Ivanti patches actively exploited EPMM zero-day, CISA orders federal agencies to act by May 10"}]}
```

