Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-6973

A configuration control vulnerability in the Ivanti Endpoint Manager Mobile before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to inject arbitrary Apache directives, leading to remote code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.055
EPSS Ranking 90.5%
CVSS Severity
CVSS v3 Score 7.2
Proposed Action
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
Ransomware Campaign
Unknown
Products affected by CVE-2026-6973


Contact Us

Shodan ® - All rights reserved