logo

U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog

ID: 3d00fafd-e280-5f70-89eb-5bd5fdcf8dc6

STIX ID: report--3d00fafd-e280-5f70-89eb-5bd5fdcf8dc6

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-01-30

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added Ivanti Endpoint Manager Mobile vulnerability CVE-2026-1281 (CVSS 9.8) — an unauthenticated code-injection leading to remote code execution — to its Known Exploited Vulnerabilities catalog; Ivanti confirmed a very limited number of in-the-wild exploitations, released patches and guidance, and federal agencies were ordered to remediate by February 2, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.