Tuesday , October 6 2026
EPMM

New Ivanti EPMM 0-Day Vuln Actively Exploited in attacks

Ivanti has released an important security notice for its Endpoint Manager Mobile (EPMM) product. It reveals several serious weaknesses being used by attackers, like CVE-2026-6973, and asks all EPMM users to install updates right away.

Ivanti said that CVE-2026-6973 is being actively used by hackers. This issue needs admin login to work.

Citrix NetScaler SAML 0-Day Flaw Under Attack

Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
Citrix NetScaler SAML 0-Day Flaw Under Attack

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The flaw only affects the on-premises EPMM product. They do not exist in Ivanti Neurons for MDM, Ivanti’s cloud-based endpoint management solution, Ivanti EPM, Ivanti Sentry, or any other Ivanti products.

Exploitation activity has been described as “very limited” at the time of public disclosure, though the company strongly warned that advanced AI models have dramatically collapsed the time-to-exploit window from days to mere hours after a vulnerability becomes public.

Ivanti announced a big change in how it manages vulnerabilities. They have added several advanced AI systems that use large language models into their product security and engineering teams.

This integration has improved the ability of its internal security teams to find and fix weaknesses that regular static analysis (SAST) and dynamic analysis (DAST) tools often miss.

Ivanti said that some of the weaknesses announced today were found using AI help. The company has a “human in the loop” rule to check all automated results, making sure AI is used wisely in its security work.

Ivanti’s EPMM has often been a target for advanced hackers. CISA has noted at least 31 Ivanti flaws in its Known Exploited Vulnerabilities (KEV) list since late 2021. In the last two years, at least 19 flaws in Ivanti products have been used in attacks.

Previous zero-day attacks on EPMM involved CVE-2025-4427 and CVE-2025-4428 in May 2025, and CVE-2023-35078 and CVE-2023-35082 in 2023. Some of these attacks were linked to groups supported by the Chinese government.

The steady focus on EPMM shows how important it is in managing mobile devices in businesses.

The security issues mentioned in Ivanti’s May 2026 notice only affect on-premises EPMM systems. Companies using Ivanti Neurons for MDM in the cloud are not affected.

Ivanti has shared clear fix instructions in its official Security Advisory. The company says the patch packages are quick to apply and won’t cause any downtime.

Mitigations

Ivanti strongly urges all on-premises EPMM administrators to act right away:

Apply the available security patch to all EPMM on-premises instances without delay
Monitor Apache access logs at /var/log/httpd/https-access_log for signs of attempted or successful exploitation.

Implement network segmentation to restrict EPMM administrative interfaces to trusted networks only.

Review and harden mobile device management policies to reduce the overall attack surface

 

Check Also

Google

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get …