Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access
2026-05-08T01:24:08Z•5ef9d2db114fcd24900008bcfe1b04f0de9e6ce30989fe57ec11340cf00ef359
IoTactive-exploitationbotnetcloud-securitycredential-theftmalwarephishingrceremote-code-executionsandbox-escapesupply-chain-compromisevulnerability-disclosure
What happened
The feed highlights a wave of active, high-severity incidents and disclosures: multiple remote code execution (RCE) flaws are being exploited in the wild (notably Ivanti EPMM, Palo Alto PAN-OS, Weaver E-cology, MetInfo and Apache HTTP/2), a new cloud-focused credential stealer (PCPJack) leveraging multiple CVEs, several supply-chain compromises (DAEMON Tools, ScarCruft), malicious PyPI packages delivering ZiChatBot, vm2 sandbox-escape vulnerabilities, a Mirai-derived IoT botnet, and large-scale phishing and token abuse campaigns. Several issues carry critical CVSS scores and are observed under
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 5ef9d2db114fcd24900008bcfe1b04f0de9e6ce30989fe57ec11340cf00ef359
- Enrichment time
- 2026-05-08T01:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.