logo

Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Released

ID: 186ee326-c7d2-51b0-8525-efe9119988b6

STIX ID: report--186ee326-c7d2-51b0-8525-efe9119988b6

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-01-30

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Ivanti disclosed two critical EPMM vulnerabilities (CVE-2026-1281 and CVE-2026-1340, CVSS 9.8) that enable unauthenticated remote code execution and have been exploited as zero-days; CISA added CVE-2026-1281 to its KEV catalog. Vendors observed exploitation patterns including specially crafted HTTP GET requests that trigger Bash script execution, resulting in rapid deployment of web shells, reverse shells, and automated droppers; mitigations include applying Ivanti RPM/patches (and reapplying post-upgrade), checking Apache access logs and configuration, auditing admin and authentication settings, restoring from known-good backups if compromised, and rotating credentials and certificates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.