logo

Ivanti Endpoint Manager Vulnerability Allows Remote Code Execution,

ID: ef5f1cb1-8765-5070-9565-05af391ce3fa

STIX ID: report--ef5f1cb1-8765-5070-9565-05af391ce3fa

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-30

Date Updated: 2026-04-22

Author: Divya

...
...

Ivanti disclosed two critical unauthenticated code-injection vulnerabilities in Endpoint Manager Mobile (CVE-2026-1281 and CVE-2026-1340, CVSS 9.8) allowing remote code execution over the network with no user interaction; limited active exploitation has been confirmed. Multiple EPMM versions are affected, Ivanti published RPM patches specific to version tracks (which must be reapplied after upgrades), and a permanent fix is slated for EPMM 12.8.0.0; organizations are urged to patch immediately or rebuild appliances for maximum security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.