Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy — Again
ID: 39c8c96f-924c-5814-b0f8-3fd22fb8d291
STIX ID: report--39c8c96f-924c-5814-b0f8-3fd22fb8d291
Feed Name: Dark Reading
Ivanti disclosed two critical RCE vulnerabilities in Endpoint Manager Mobile (CVE-2026-1281 and CVE-2026-1340) that scored 9.8 CVSS and were quickly exploited in the wild; attacks affected multiple European government agencies (including the European Commission, Finland's Valtori, and Dutch agencies) and led to leaks of staff names, emails, phone numbers and other device details for thousands of individuals. A public proof-of-concept and observed exploitation spikes (including activity traced to a single bulletproof-hosted IP) accelerated attacks, prompting CISA KEV listing and vendor advisories urging immediate patching and forensic review.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
