logo

January blues return as Ivanti coughs up exploited EPMM zero-days

ID: 63af59eb-3922-5186-87ff-28c1b60aa802

STIX ID: report--63af59eb-3922-5186-87ff-28c1b60aa802

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-01-30

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Ivanti patched two critical unauthenticated RCE zero-days in Endpoint Manager Mobile (CVE-2026-1281 and CVE-2026-1340, CVSS 9.8) that are being exploited in the wild; the vendor reports a small number of confirmed compromises, provides detection guidance (review Apache access logs, look for suspicious GET/POST requests, unexpected 404s vs 200s, web shells, and unexpected WAR/JAR files or outbound connections) and recommends applying patches, restoring from backups or rebuilding impacted systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.