Skip to main content
See every side of every news story
Published loading...Updated

Ivanti Warns of New EPMM Flaw Exploited in Zero-Day Attacks

Ivanti said the flaw requires authenticated admin access and released fixes for five vulnerabilities, while CISA added the zero-day to its catalog within hours.

  • On Thursday, Ivanti released patches for five vulnerabilities in Endpoint Manager Mobile , including one zero-day actively exploited in the wild.
  • Unlike previous unauthenticated code-injection flaws, this zero-day requires authenticated administrative access to exploit, making customers who rotated credentials following January's CVE-2026-1281 and CVE-2026-1340 attacks significantly less vulnerable.
  • Internet security watchdog Shadowserver currently tracks over 850 IP addresses with EPMM fingerprints exposed online, while the Cybersecurity and Infrastructure Security Agency has flagged 34 Ivanti defects on its known exploited vulnerabilities catalog since late 2021.
  • CISA added the zero-day to its known exploited vulnerabilities catalog within hours of Thursday's disclosure, while Ivanti confirmed no evidence that four additional patched defects—CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, and CVE-2026-7821—have been exploited.
  • Ivanti Chief Security Officer Daniel Spicer stated the company maintains an 'aggressive' communication stance regarding disclosures, noting the firm uses advanced AI and internal detection processes to identify and remediate vulnerabilities quickly.
Insights by Ground AI

11 Articles

Ivanti has released security updates for the Endpoint Manager Mobile (EPMM). They also close already attacked gaps.

·Germany
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news on Thursday, May 7, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal