U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-1281 | Unauthenticated RCE in Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) contains a code injection flaw (CWE-94) that permits unauthenticated remote code execution: an attacker who can reach the EPMM server over the network can send crafted requests that execute arbitrary code without credentials or user interaction. Successful exploitation yields control of the MDM server, exposing directory/contact data, device inventory, and the ability to push commands or profiles to enrolled corporate mobile devices. Any organization running an affected EPMM deployment is in scope, with internet-facing instances at greatest risk; the available data does not specify affected version ranges, so operators should consult Ivanti's advisory. Exploitation is confirmed in the wild — the flaw was added to CISA's KEV on 2026-01-29 and carries an 81.8% EPSS — and press reporting describes EPMM under active zero-day attack, apparently alongside a second critical EPMM vulnerability (CVE-2026-6973), including incidents disclosed by Dutch government and EU bodies. Do: Patch EPMM per Ivanti's security advisory immediately — CISA's KEV required action is to apply vendor mitigations by the listed deadline, follow BOD 22-01 guidance for cloud services, or discontinue use — and note that the provided data does not include patched version numbers, so rely on the vendor advisory for exact targets. Until patched, remove direct internet exposure from EPMM (restrict to VPN/management networks) and hunt for compromise, checking logs for activity from bulletproof-hosting infrastructure, since public reporting says the large majority of observed EPMM exploits trace to a single IP there. Also verify whether the separately reported EPMM zero-day (CVE-2026-6973) affects your deployment, as attackers appear to be chaining the two flaws. | 9.8 | 82% | KEV |
| large≈ a few thousand internet-exposed EPMM servers, collectively managing on the order of 100k+ corporate mobile devices | |
| CVE-2026-24858 | FortiCloud SSO Authentication Bypass Across Multiple Fortinet Products CVE-2026-24858 is an authentication bypass (CWE-288) in FortiCloud single sign-on that lets an attacker who owns a FortiCloud account with any registered device log in to other customers' Fortinet devices that have FortiCloud SSO authentication enabled. It affects a wide range of 7.x/8.x builds of FortiOS, FortiProxy, FortiWeb, FortiAnalyzer, FortiManager, FortiNAC-F, and the Siemens RUGGEDCOM APE 1808. An attacker gains unauthorized access to devices registered to other accounts, and related reporting describes FortiGate devices being exploited to breach networks and steal service account credentials. Any organization running an affected build with FortiCloud SSO enabled is exposed. Exploitation is confirmed in the wild: CISA added the flaw to the KEV catalog on 2026-01-27 and Fortinet patched it after active FortiOS SSO exploitation was detected, and EPSS assigns an 86.1% probability of exploitation within 30 days. Do: Upgrade all affected Fortinet products to the fixed releases specified in Fortinet's PSIRT advisory for CVE-2026-24858; as an interim mitigation, disable FortiCloud SSO authentication on affected devices and audit which devices are registered to your FortiCloud account. Review device logs for unexpected administrative logins or signs of service-account credential theft on FortiGate, and federal agencies must apply mitigations per BOD 22-01 (including CISA's cloud services guidance) or discontinue use of the product. | 9.8 | 86% | KEV |
| masshundreds of thousands of devices potentially affected (Fortinet's FortiGate install base is in the millions and public internet scans have long shown hundreds… |
Full article296 words · extracted from securityaffairs.com · click to collapse

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Ivanti EPMM vulnerability, tracked as CVE-2026-1281 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog.
The vulnerability is a code injection that impacts Ivanti Endpoint Manager Mobile. An unauthenticated attacker can exploit the vulnerability to achieve remote code execution.
“A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.” reads the advisory.
The company confirmed that it is aware of attacks in the wild exploiting this vulnerability.
“We are aware of a very limited number of customers who have been exploited at the time of disclosure.” continues the advisory.
Ivanti said the investigation is ongoing and no reliable indicators of compromise are available yet, though technical guidance has been shared. Sentry and Ivanti Neurons for MDM are not vulnerable, and cloud customers are unaffected. Ivanti has released a patch, expanded customer support, and is working with security partners and law enforcement.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerability by February 2, 2026.
US CISA also published an alert related to this flaw titled “Fortinet Releases Guidance to Address Ongoing Exploitation of Authentication Bypass Vulnerability CVE-2026-24858“
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, US CISA Known Exploited Vulnerabilities catalog)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/187488/security/u-s-cisa-adds-a-flaw-in-ivanti-epmm-to-its-known-exploited-vulnerabilities-catalog.html