Ivanti Endpoint Manager Vulnerability Allows Remote Code Execution,
ID: ef5f1cb1-8765-5070-9565-05af391ce3fa
STIX ID: report--ef5f1cb1-8765-5070-9565-05af391ce3fa
Feed Name: GBHackers
Ivanti disclosed two critical unauthenticated code-injection vulnerabilities in Endpoint Manager Mobile (CVE-2026-1281 and CVE-2026-1340, CVSS 9.8) allowing remote code execution over the network with no user interaction; limited active exploitation has been confirmed. Multiple EPMM versions are affected, Ivanti published RPM patches specific to version tracks (which must be reapplied after upgrades), and a permanent fix is slated for EPMM 12.8.0.0; organizations are urged to patch immediately or rebuild appliances for maximum security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
