ZeroHour

CVE-2026-1281

KEVlarge1

Unauthenticated RCE in Ivanti Endpoint Manager Mobile (EPMM)

CISA: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
82%p100
Published
()
KEV added
AI analysis

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection flaw (CWE-94) that permits unauthenticated remote code execution: an attacker who can reach the EPMM server over the network can send crafted requests that execute arbitrary code without credentials or user interaction. Successful exploitation yields control of the MDM server, exposing directory/contact data, device inventory, and the ability to push commands or profiles to enrolled corporate mobile devices. Any organization running an affected EPMM deployment is in scope, with internet-facing instances at greatest risk; the available data does not specify affected version ranges, so operators should consult Ivanti's advisory. Exploitation is confirmed in the wild — the flaw was added to CISA's KEV on 2026-01-29 and carries an 81.8% EPSS — and press reporting describes EPMM under active zero-day attack, apparently alongside a second critical EPMM vulnerability (CVE-2026-6973), including incidents disclosed by Dutch government and EU bodies.

What to do: Patch EPMM per Ivanti's security advisory immediately — CISA's KEV required action is to apply vendor mitigations by the listed deadline, follow BOD 22-01 guidance for cloud services, or discontinue use — and note that the provided data does not include patched version numbers, so rely on the vendor advisory for exact targets. Until patched, remove direct internet exposure from EPMM (restrict to VPN/management networks) and hunt for compromise, checking logs for activity from bulletproof-hosting infrastructure, since public reporting says the large majority of observed EPMM exploits trace to a single IP there. Also verify whether the separately reported EPMM zero-day (CVE-2026-6973) affects your deployment, as attackers appear to be chaining the two flaws.

Affected
Ivanti Endpoint Manager Mobile (EPMM)
Estimated exposure
large≈ a few thousand internet-exposed EPMM servers, collectively managing on the order of 100k+ corporate mobile devices — EPMM (formerly MobileIron) is an enterprise MDM widely deployed by large organizations and governments; historical public internet scans have shown only low thousands of exposed EPMM instances, but each typically manages large corporate…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

CISA Known Exploited Vulnerability
Affected
Ivanti Endpoint Manager Mobile (EPMM)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
ivanti
Products
endpoint manager mobile
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

2026-001: Critical vulnerabilities in Ivanti EPMM

Ivanti EPMM has two critical CVSS 9.8 flaws allowing unauthenticated remote code execution; limited exploitation has already been observed.

On 29 January 2026, Ivanti patched CVE-2026-1281 and CVE-2026-1340, two code injection vulnerabilities (both CVSS 9.8) in Endpoint Manager Mobile that allow unauthenticated remote code execution. CERT-EU reports one of the flaws was exploited in a limited number of cases. Affected versions include EPMM 12.5.1.0, 12.6.1.0 and 12.7.0.0 and prior; the permanent fix is planned for release 12.8.0.0 in Q1 2026.

CERT-EU Advisories · Jan 30, 2026Vulnerability in the wildCVE-2026-1281CVE-2026-1340