logo

Ivanti warns of two EPMM flaws exploited in zero-day attacks

ID: e7324810-cbd1-57af-8ed0-31557144b6e2

STIX ID: report--e7324810-cbd1-57af-8ed0-31557144b6e2

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-01-29

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Ivanti disclosed two critical code-injection zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in Endpoint Manager Mobile (both CVSS 9.8) that have been exploited in the wild, enabling unauthenticated remote code execution and exposure of administrator/user data and managed-device information. Ivanti published RPM hotfixes with no downtime required, detection guidance (including an Apache access-log regex to find exploitation attempts), and recommends restoring from known-good backups or rebuilding compromised appliances; CISA added CVE-2026-1281 to its Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.