HIGH: Ivanti EPMM Zero-Day RCE Lands on CISA KEV With 850 Exposed Servers
CVE-2026-6973 is an authenticated admin RCE in on-prem Ivanti EPMM rated CVSS 7.2 and confirmed under active exploitation. CISA added it to the KEV catalog with a federal patch deadline of May 10, 2026. Patch to 12.6.1.1, 12.7.0.1, or 12.8.0.1 immediately and rotate admin credentials.