logo

CVE-2026-1281 & CVE-2026-1340: Ivanti EPMM Zero-Day Vulnerabilities Enable Unauthenticated RCE

ID: 8ac5517a-7060-5418-ad9a-8224a0dec47f

STIX ID: report--8ac5517a-7060-5418-ad9a-8224a0dec47f

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-01-30

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Ivanti disclosed two critical unauthenticated RCE vulnerabilities in Ivanti Endpoint Manager Mobile (CVE-2026-1281 and CVE-2026-1340, CVSS 9.8) that have seen limited real-world exploitation; CVE-2026-1281 is listed in CISA's KEV catalog. Affected EPMM versions include 12.5.x through 12.7.x; Ivanti issued interim RPM patches (which do not persist across upgrades) and plans a permanent fix in 12.8.0.0, and provided detection guidance (Apache access log regex, forensic checks) plus recovery recommendations (restore from known-good backup or rebuild).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.