ZeroHour
CERT-EU Advisoriespublished ()ingested

2026-001: Critical vulnerabilities in Ivanti EPMM

highVulnerability exploited in the wildimportance 72CVE-2026-1281CVE-2026-1340
AI summary · glm-5.3-flash

Ivanti EPMM has two critical CVSS 9.8 flaws allowing unauthenticated remote code execution; limited exploitation has already been observed.

On 29 January 2026, Ivanti patched CVE-2026-1281 and CVE-2026-1340, two code injection vulnerabilities (both CVSS 9.8) in Endpoint Manager Mobile that allow unauthenticated remote code execution. CERT-EU reports one of the flaws was exploited in a limited number of cases. Affected versions include EPMM 12.5.1.0, 12.6.1.0 and 12.7.0.0 and prior; the permanent fix is planned for release 12.8.0.0 in Q1 2026.

  • Two CVSS 9.8 code injection flaws enable unauthenticated RCE on EPMM
  • One vulnerability exploited in a limited number of cases
  • Hotfix RPM does not survive version upgrades and must be reapplied
  • Permanent fix expected in EPMM 12.8.0.0 in Q1 2026

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-1340
+1 in the same advisory: …1281
Unauthenticated Code Injection RCE in Ivanti Endpoint Manager Mobile

CVE-2026-1340 is a code injection flaw (CWE-94) in Ivanti Endpoint Manager Mobile (EPMM), Ivanti's enterprise mobile device management platform, that permits unauthenticated remote code execution. Because the flaw is network-reachable and requires no privileges or user interaction (AV:N/AC:L/PR:N/UI:N), a remote attacker can send a crafted request to a vulnerable EPMM server and execute arbitrary code, with high impact to confidentiality, integrity, and availability. Any organization operating an affected EPMM server is affected, especially those exposing the management or device-enrollment interface to the internet. The flaw was added to CISA's KEV catalog on 2026-04-08 with an 86.2% probability of exploitation within 30 days; news reporting describes active zero-day attacks against EPMM (alongside related CVE-2026-6973), including a confirmed Dutch government incident exposing employee contact data, while ransomware use remains unconfirmed. A large share of observed exploit traffic has been traced to a single IP address on bulletproof hosting infrastructure.

Do: Apply Ivanti's patched EPMM release per the vendor advisory immediately and verify the fix on any internet-facing EPMM portal; US federal agencies must follow BOD 22-01 mitigation deadlines. Until patched, restrict EPMM portal access to trusted networks/VPNs and review access logs for suspicious requests or unrecognized source IPs, noting that much exploit activity has originated from a single bulletproof-hosting IP.

9.886% KEV
  • Ivanti Endpoint Manager Mobile (EPMM)
large≈ tens of thousands of EPMM server deployments, a large share of them internet-exposed
Full article209 words · extracted from cert.europa.eu · click to collapse

Release Date: 30-01-2026 09:09:06

History:

  • 30/01/2026 --- v1.0 -- Initial publication

Summary

On 29 January 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their EPMM products. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device. One of these vulnerabilities have been exploited in a limited number of cases [1].

Technical Details

The vulnerability CVE-2026-1281, with a CVSS score of 9.8, is a code injection vulnerability in Ivanti Endpoint Manager Mobile.

The vulnerability CVE-2026-1340, with a CVSS score of 9.8, is a code injection vulnerability in Ivanti Endpoint Manager Mobile.

Affected Products

The following versions of Ivanti's Endpoint Manager Mobile (EPMM) are affected:

  • 12.5.1.0 and prior.
  • 12.6.1.0 and prior.
  • 12.7.0.0 and prior.

Recommendations

CERT-EU recommends securing forensic evidence to detect any signs of exploitation. CERT-EU also recommends following the vendor's guidance to apply the hotfix (i.e. RPM 12.x.0 or RPM 12.x.1) on vulnerable appliances. As noted by the vendor, the applied RPM script will not survive a version upgrade which means that the script will need to be reapplied after an upgrade to a new version. The permanent fix for this vulnerability will be included in the release 12.8.0.0 which is planned for Q1 2026.

References

[1] https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US

Text extracted automatically; images, tables and formatting may be missing. Original: https://cert.europa.eu/publications/security-advisories/2026-001/