logo

Massive Spike in Attacks Exploiting Ivanti EPMM Systems 0-day Vulnerability

ID: aa57d9b1-88b2-5b64-8bbe-d94356d63b52

STIX ID: report--aa57d9b1-88b2-5b64-8bbe-d94356d63b52

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2026-02-11

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Ivanti EPMM CVE-2026-1281 (CVSS 9.8) is being actively and widely exploited in a coordinated campaign observed since February 9, 2026, with over 28,300 unique source IPs attempting unauthenticated code injection via a vulnerable Bash handler at /mifs/c/appstore/fob/, enabling remote command execution and deployment of sleeper webshells that provide persistent access; Shadowserver, GreyNoise, and other researchers attribute high-volume activity to a suspected initial access broker using bulletproof hosting, CISA added the CVE to its Known Exploited Vulnerabilities catalog, and Ivanti released temporary patches while a permanent fix is scheduled for v12.8.0.0—organizations should apply patches immediately, block malicious source IPs, and hunt for webshells and suspicious requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.