logo

Ivanti Issues Urgent Fix for Critical Zero-Day Flaws Under Active Attack

ID: 8f01fa03-f696-57c8-a92b-0f1f7630e80e

STIX ID: report--8f01fa03-f696-57c8-a92b-0f1f7630e80e

Feed Name: HackRead

Threat Score
90/100

Date Published: 2026-02-02

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Ivanti Endpoint Manager Mobile (on‑premise) is being actively exploited via two critical code-injection RCEs (CVE-2026-1281, CVE-2026-1340) that allow unauthenticated remote code execution by sending crafted requests that trigger Bash script execution; Ivanti released an emergency RPM patch (temporary) and plans a permanent fix in v12.8.0.0, and affected organizations are urged to patch immediately and consider systems compromised if exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.