Critical Ivanti Endpoint Manager 0-day RCE Vulnerabilities Actively Exploited in Attacks
ID: 58340f40-5ee2-528e-ab8b-7c542396aef0
STIX ID: report--58340f40-5ee2-528e-ab8b-7c542396aef0
Feed Name: cybersecurityNews.com
Two critical unauthenticated code‑injection vulnerabilities (CVE‑2026‑1281 and CVE‑2026‑1340) in Ivanti Endpoint Manager Mobile allow remote code execution (CVSS 9.8) and are being actively exploited; Ivanti has released version-specific RPM patches and plans a permanent fix in v12.8.0.0 (Q1 2026). The company reports a limited number of customer environments compromised at disclosure and has provided forensic guidance, though reliable indicators of compromise are not yet available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
