Ivanti EPMM exploitation: Researchers warn of "sleeper" webshells
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-1340 +1 in the same advisory: …1281 | Unauthenticated Code Injection RCE in Ivanti Endpoint Manager Mobile CVE-2026-1340 is a code injection flaw (CWE-94) in Ivanti Endpoint Manager Mobile (EPMM), Ivanti's enterprise mobile device management platform, that permits unauthenticated remote code execution. Because the flaw is network-reachable and requires no privileges or user interaction (AV:N/AC:L/PR:N/UI:N), a remote attacker can send a crafted request to a vulnerable EPMM server and execute arbitrary code, with high impact to confidentiality, integrity, and availability. Any organization operating an affected EPMM server is affected, especially those exposing the management or device-enrollment interface to the internet. The flaw was added to CISA's KEV catalog on 2026-04-08 with an 86.2% probability of exploitation within 30 days; news reporting describes active zero-day attacks against EPMM (alongside related CVE-2026-6973), including a confirmed Dutch government incident exposing employee contact data, while ransomware use remains unconfirmed. A large share of observed exploit traffic has been traced to a single IP address on bulletproof hosting infrastructure. Do: Apply Ivanti's patched EPMM release per the vendor advisory immediately and verify the fix on any internet-facing EPMM portal; US federal agencies must follow BOD 22-01 mitigation deadlines. Until patched, restrict EPMM portal access to trusted networks/VPNs and review access logs for suspicious requests or unrecognized source IPs, noting that much exploit activity has originated from a single bulletproof-hosting IP. | 9.8 | 86% | KEV |
| large≈ tens of thousands of EPMM server deployments, a large share of them internet-exposed |
Full article541 words · extracted from helpnetsecurity.com · click to collapse
A massive wave of exploitation attempts has followed the disclosure of CVE-2026-1281, a critical pre-authentication Ivanti EPMM vulnerability, the Shadowserver Foundation has warned.
Some of it is automated scanning for vulnerable systems, but according to Greynoise and Defused, a suspected initial access broker has been prepping unpatched instances with a “sleeper” webshell for follow-on exploitation by other threat actors.
“On February 9, Defused Cyber reported a campaign deploying dormant in-memory Java class loaders to compromised EPMM instances at the path /mifs/403.jsp. The implants require a specific trigger parameter to activate, and no follow-on exploitation was observed at the time of their report,” Greynoise noted.
From their own vantage point – Greynoise sensors placed in data center networks and public IP space that passively observe unsolicited internet traffic around the world – the company spotted exploitation sessons that involved payloads that “phone home via DNS to confirm “this target is exploitable.”
“They do not deploy malware. They do not exfiltrate data. They verify access,” Greynoise researchers noted. “This is consistent with initial access operations that verify exploitability first and deploy follow-on tooling later.”
CVE-2026-1281 exploitation picks up steam
Ivanti disclosed CVE-2026-1281 and CVE-2026-1340, two code injection vulnerabilities in its Endpoint Manager Mobile solution, on January 29, 2026, and said that they were aware of in-the-wild exploitation. CISA added CVE-2026-1281 to its Known Exploited Vulnerabilities catalog on the same day.
The company provided a temporary fix/patch for the flaws on January 29 (and released security updates on February 4), but on January 30, watchTowr researchers released their analysis of one of the patches.
It was revealed last week that the Dutch Data Protection Authority (AP) and the Council for the Judiciary (Rvdr) have had their EPMM instances breached on or before January 29, likely via CVE-2026-1281, and that the European Commission’s mobile device management platform was hacked (though the solution remains unnamed).
Another confirmed victim is Valtori, Finland’s central government ICT service center.
Ivanti, with the help of the Dutch National Cyber Security Center (NCSC-NL) has released a detection script to help customers find evidence of exploitation in their Ivanti EPMM environment. NCSC-NL warned that all organizations using Ivanti EPMM should assume they’ve been compromised and mount a forensic investigation to check.
Defused Cyber has shared log indicators and indicators of compromise and has advised organizations to patch their Ivanti EPMM instance, restart application servers to flush in-memory implants, and review access logs with the provided indicators.
UPDATE (February 12, 2026, 02:40 a.m. ET):
“Ivanti’s recommendation remains the same: customers who have not yet patched should do so immediately, and then review their appliance for any signs of exploitation that may have occurred prior to patching. Applying the patch is the most effective way to prevent exploitation, regardless of how IOCs change over time, especially once a POC is available. The patch requires no downtime and takes only seconds to apply,” an Ivanti spokesperson commented.
“Ivanti has provided customers with high fidelity indicators of compromise, technical analysis at disclosure, and an Exploitation Detection script developed with NCSC NL, and continues to support customers as we respond to this threat.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/02/11/ivanti-epmm-sleeper-webshell/