U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-1340 | Unauthenticated Code Injection RCE in Ivanti Endpoint Manager Mobile CVE-2026-1340 is a code injection flaw (CWE-94) in Ivanti Endpoint Manager Mobile (EPMM), Ivanti's enterprise mobile device management platform, that permits unauthenticated remote code execution. Because the flaw is network-reachable and requires no privileges or user interaction (AV:N/AC:L/PR:N/UI:N), a remote attacker can send a crafted request to a vulnerable EPMM server and execute arbitrary code, with high impact to confidentiality, integrity, and availability. Any organization operating an affected EPMM server is affected, especially those exposing the management or device-enrollment interface to the internet. The flaw was added to CISA's KEV catalog on 2026-04-08 with an 86.2% probability of exploitation within 30 days; news reporting describes active zero-day attacks against EPMM (alongside related CVE-2026-6973), including a confirmed Dutch government incident exposing employee contact data, while ransomware use remains unconfirmed. A large share of observed exploit traffic has been traced to a single IP address on bulletproof hosting infrastructure. Do: Apply Ivanti's patched EPMM release per the vendor advisory immediately and verify the fix on any internet-facing EPMM portal; US federal agencies must follow BOD 22-01 mitigation deadlines. Until patched, restrict EPMM portal access to trusted networks/VPNs and review access logs for suspicious requests or unrecognized source IPs, noting that much exploit activity has originated from a single bulletproof-hosting IP. | 9.8 | 86% | KEV |
| large≈ tens of thousands of EPMM server deployments, a large share of them internet-exposed |
Full article374 words · extracted from securityaffairs.com · click to collapse

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in Ivanti EPMM, tracked as CVE-2026-1340 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog.
The critical vulnerability is a code injection in Ivanti Endpoint Manager Mobile that allows attackers to achieve unauthenticated remote code execution.
Below is the list of affected versions:
| Product Name | Affected Version(s) | Affected CPE(s) | Resolved Version(s) |
| Ivanti Endpoint Manager Mobile | 12.5.0.0 and prior 12.6.0.0 and prior 12.7.0.0 and prior | cpe:2.3:a:ivanti:endpoint_manager_mobile:12.7.0.0:*:*:*:*:*:*:* | RPM 12.x.0.x |
| Ivanti Endpoint Manager Mobile | 12.5.1.0 and prior 12.6.1.0 and prior | cpe:2.3:a:ivanti:endpoint_manager_mobile:12.5.1.0:*:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager_mobile:12.6.1.0:*:*:*:*:*:*:* | RPM 12.x.1.x |
The software firm is aware of attacks in the wild exploiting this flaw.
“We are aware of a very limited number of customers who have been exploited at the time of disclosure. However, a POC was made available by a third party shortly after disclosure.” warns the company. “We urge all customers to apply the patch as soon as possible and run the Exploitation Detection RPM package as a tool to assist in identifying potential compromise.”
The company released a new RPM detection tool that helps customers check for possible exploitation by scanning for known indicators and generating logs for review. Any suspicious activity before patching may indicate compromise and requires investigation, while alerts after patching are likely just harmless scanning attempts.
The company pointed out that running the RPM tool alone doesn’t guarantee the appliance is clean. It helps detect known indicators of compromise, but absence of findings isn’t proof of safety. Results should be reviewed with the security team and combined with other analysis and tools.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerability by April 11, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, US CISA Known Exploited Vulnerabilities catalog)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/190519/security/u-s-cisa-adds-a-flaw-in-ivanti-epmm-to-its-known-exploited-vulnerabilities-catalog-2.html