Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access

2026-05-08T01:24:08Z5ef9d2db114fcd24900008bcfe1b04f0de9e6ce30989fe57ec11340cf00ef359
IoTactive-exploitationbotnetcloud-securitycredential-theftmalwarephishingrceremote-code-executionsandbox-escapesupply-chain-compromisevulnerability-disclosure

What happened

The feed highlights a wave of active, high-severity incidents and disclosures: multiple remote code execution (RCE) flaws are being exploited in the wild (notably Ivanti EPMM, Palo Alto PAN-OS, Weaver E-cology, MetInfo and Apache HTTP/2), a new cloud-focused credential stealer (PCPJack) leveraging multiple CVEs, several supply-chain compromises (DAEMON Tools, ScarCruft), malicious PyPI packages delivering ZiChatBot, vm2 sandbox-escape vulnerabilities, a Mirai-derived IoT botnet, and large-scale phishing and token abuse campaigns. Several issues carry critical CVSS scores and are observed under

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
5ef9d2db114fcd24900008bcfe1b04f0de9e6ce30989fe57ec11340cf00ef359
Enrichment time
2026-05-08T01:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access · Baitaphish