Massive Spike in Attacks Exploiting Ivanti EPMM Systems 0-day Vulnerability
ID: aa57d9b1-88b2-5b64-8bbe-d94356d63b52
STIX ID: report--aa57d9b1-88b2-5b64-8bbe-d94356d63b52
Feed Name: cybersecurityNews.com
Ivanti EPMM CVE-2026-1281 (CVSS 9.8) is being actively and widely exploited in a coordinated campaign observed since February 9, 2026, with over 28,300 unique source IPs attempting unauthenticated code injection via a vulnerable Bash handler at /mifs/c/appstore/fob/, enabling remote command execution and deployment of sleeper webshells that provide persistent access; Shadowserver, GreyNoise, and other researchers attribute high-volume activity to a suspected initial access broker using bulletproof hosting, CISA added the CVE to its Known Exploited Vulnerabilities catalog, and Ivanti released temporary patches while a permanent fix is scheduled for v12.8.0.0—organizations should apply patches immediately, block malicious source IPs, and hunt for webshells and suspicious requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
