logo

Critical Ivanti EPMM Vulnerabilities: CVE-2026-1281 & CVE-2026-1340

ID: 157689fc-66b5-5984-9fcc-4c46bf3e0810

STIX ID: report--157689fc-66b5-5984-9fcc-4c46bf3e0810

Feed Name: Abstract Security Blog

Threat Score
90/100

Date Published: 2026-01-29

Date Updated: 2026-04-26

...
...

In late January 2026 CISA added CVE-2026-1281 and CVE-2026-1340—critical, actively exploited vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM). Attackers send HTTP GET requests with embedded bash commands to /mifs/c/aftstore/fob/ and /mifs/c/appstore/fob/, producing a distinctive 404 response signature; the report provides a detection regex, IOCs, post-exploitation indicators, and urgent remediation steps including patching, off-box log forwarding, isolation, and credential rotation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.