Critical Ivanti EPMM Vulnerabilities Expose Systems to Arbitrary Code Execution Attacks
ID: ab38d090-2670-51ea-9f4a-2c175f303b7a
STIX ID: report--ab38d090-2670-51ea-9f4a-2c175f303b7a
Feed Name: GBHackers
Threat Score
In February 2026 attackers actively exploited two critical pre-authentication RCE zero-days in Ivanti Endpoint Manager Mobile (CVE-2026-1281 and CVE-2026-1340) to install a Java webshell, gain root execution, and rapidly exfiltrate sensitive data (including MIFs database tables and admin credentials) using automated, AntSword-derived tooling and web-accessible archive transfers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
