CISA adding CVE-2026-6973 to the KEV catalog should be treated as a clear escalation signal, not just another vulnerability bulletin. The issue affects Ivanti Endpoint Manager Mobile and has reportedly seen limited real-world exploitation, with CISA urging remediation by May 10, 2026. Since EPMM sits in a sensitive device-management position, compromise can have serious downstream impact across mobile users, policies, certificates, and enterprise access.
Organizations using Ivanti EPMM should immediately verify exposure, apply the fixed versions, review administrator access, and check logs for unusual activity. Endpoint management platforms are high-value targets because attackers do not need to compromise every device one by one when they can go after the system trusted to manage them. Convenient for IT, convenient for attackers too, because apparently efficiency is a shared value.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-42208 BerriAI LiteLLM SQL Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria .
Source: CISA Adds One Known Exploited Vulnerability to Catalog via CISA Advisories — published 08 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.