ZeroHour
Organization

European Union Agency for Cybersecurity

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

2026-001: Critical vulnerabilities in Ivanti EPMM

Ivanti EPMM has two critical CVSS 9.8 flaws allowing unauthenticated remote code execution; limited exploitation has already been observed.

On 29 January 2026, Ivanti patched CVE-2026-1281 and CVE-2026-1340, two code injection vulnerabilities (both CVSS 9.8) in Endpoint Manager Mobile that allow unauthenticated remote code execution. CERT-EU reports one of the flaws was exploited in a limited number of cases. Affected versions include EPMM 12.5.1.0, 12.6.1.0 and 12.7.0.0 and prior; the permanent fix is planned for release 12.8.0.0 in Q1 2026.

CERT-EU Advisories · Jan 30, 2026Vulnerability in the wildCVE-2026-1281CVE-2026-1340

Related CVEs

  • Unauthenticated Code Injection RCE in Ivanti Endpoint Manager Mobile
    CVE-2026-1340 is a code injection flaw (CWE-94) in Ivanti Endpoint Manager Mobile (EPMM), Ivanti's enterprise mobile device management platform, that permits unauthenticated remote code execution. Because the flaw is network-reachable and requires no privileges or user interaction (AV:N/AC:L/PR:N/UI:N), a remote attacker can send a crafted request to a vulnerable EPMM server and execute arbitrary code, with high impact to confidentiality, integrity, and availability. Any organization operating an affected EPMM server is affected, especially those exposing the management or device-enrollment interface to the internet. The flaw was added to CISA's KEV catalog on 2026-04-08 with an 86.2% probability of exploitation within 30 days; news reporting describes active zero-day attacks against EPMM (alongside related CVE-2026-6973), including a confirmed Dutch government incident exposing employee contact data, while ransomware use remains unconfirmed. A large share of observed exploit traffic has been traced to a single IP address on bulletproof hosting infrastructure.
    · Ivanti Endpoint Manager Mobile (EPMM) KEVlarge
  • Unauthenticated RCE in Ivanti Endpoint Manager Mobile (EPMM)
    Ivanti Endpoint Manager Mobile (EPMM) contains a code injection flaw (CWE-94) that permits unauthenticated remote code execution: an attacker who can reach the EPMM server over the network can send crafted requests that execute arbitrary code without credentials or user interaction. Successful exploitation yields control of the MDM server, exposing directory/contact data, device inventory, and the ability to push commands or profiles to enrolled corporate mobile devices. Any organization running an affected EPMM deployment is in scope, with internet-facing instances at greatest risk; the available data does not specify affected version ranges, so operators should consult Ivanti's advisory. Exploitation is confirmed in the wild — the flaw was added to CISA's KEV on 2026-01-29 and carries an 81.8% EPSS — and press reporting describes EPMM under active zero-day attack, apparently alongside a second critical EPMM vulnerability (CVE-2026-6973), including incidents disclosed by Dutch government and EU bodies.
    · Ivanti Endpoint Manager Mobile (EPMM) KEVlarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.