Fallout from latest Ivanti zero-days spreads to nearly 100 victims
ID: 131c6709-92fa-5d81-8798-631a9cd0823b
STIX ID: report--131c6709-92fa-5d81-8798-631a9cd0823b
Feed Name: CyberScoop
Ivanti customers, including national government agencies and EU infrastructure, are being actively targeted through two critical Ivanti Endpoint Manager Mobile zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340, CVSS 9.8). Researchers and organizations report in-the-wild exploitation, deployment of webshells and reverse shells, hundreds of exploit attempts observed by honeypots, at least dozens of confirmed compromises identified by Shadowserver, and many Internet-exposed EPMM instances remaining vulnerable as vendor and community detection/hunting efforts continue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
