logo

CVE-2026-1281 and CVE-2026-1340 Affecting Ivanti Endpoint Manager Mobile (EPMM)

ID: ef10f5f4-fa0f-5fe6-8e6c-a63ad638b5ec

STIX ID: report--ef10f5f4-fa0f-5fe6-8e6c-a63ad638b5ec

Feed Name: Kudelski Security

Threat Score
75/100

Date Published: 2026-01-30

Date Updated: 2026-07-22

...
...

This advisory identifies two critical vulnerabilities in Ivanti Endpoint Manager Mobile (CVE-2026-1281: authentication bypass; CVE-2026-1340: unauthenticated code injection/RCE), lists affected versions and CPEs, describes impacts including arbitrary code execution and data exposure, and provides mitigation and detection guidance (patching, network segmentation, access controls, enhanced logging) plus a log-triage regex for Apache access logs to detect exploitation attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.