logo

Ivanti’s EPMM is under active attack, thanks to two critical zero-days

ID: b7cbe0a2-3e82-53dc-8b81-9dcf6e3d0ac1

STIX ID: report--b7cbe0a2-3e82-53dc-8b81-9dcf6e3d0ac1

Feed Name: CyberScoop

Threat Score
88/100

Date Published: 2026-02-03

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Ivanti disclosed two critical EPMM zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340, CVSS 9.8) that permit unauthenticated remote code execution and have been actively exploited in the wild; some customers were attacked prior to public disclosure. CISA added one of the flaws to its Known Exploited Vulnerabilities catalog, Shadowserver observed spikes in exploitation attempts, and many Ivanti EPMM instances remain internet-exposed; Ivanti issued temporary mitigations and plans a permanent fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.