CVE-2026-1281 & CVE-2026-1340: Ivanti EPMM Zero-Day Vulnerabilities Enable Unauthenticated RCE
ID: 8ac5517a-7060-5418-ad9a-8224a0dec47f
STIX ID: report--8ac5517a-7060-5418-ad9a-8224a0dec47f
Feed Name: SOCRadar Blog
Ivanti disclosed two critical unauthenticated RCE vulnerabilities in Ivanti Endpoint Manager Mobile (CVE-2026-1281 and CVE-2026-1340, CVSS 9.8) that have seen limited real-world exploitation; CVE-2026-1281 is listed in CISA's KEV catalog. Affected EPMM versions include 12.5.x through 12.7.x; Ivanti issued interim RPM patches (which do not persist across upgrades) and plans a permanent fix in 12.8.0.0, and provided detection guidance (Apache access log regex, forensic checks) plus recovery recommendations (restore from known-good backup or rebuild).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
