Bleepingcomputer Critical Ivanti EPMM Vulnerabilities Under Active Exploitation
Article Content
- •CVE-2026-1281 and CVE-2026-1340 allow unauthenticated RCE with a CVSS score of 9.8.
- •Exploitation has been confirmed across various sectors, including government and healthcare.
- •Ivanti has released emergency patches, but they do not persist through version upgrades.
Two critical vulnerabilities in Ivanti's Endpoint Manager Mobile (EPMM), CVE-2026-1281 and CVE-2026-1340, have been actively exploited in the wild, allowing unauthenticated remote code execution (RCE) with a CVSS score of 9.8. These vulnerabilities were disclosed on January 29, 2026, and have since been added to CISA's Known Exploited Vulnerabilities catalog. Exploitation has been observed across various sectors, including government and healthcare, with attackers leveraging these flaws to gain unauthorized access to sensitive device management data. The vulnerabilities stem from code injection issues in the In-House Application Distribution and Android File Transfer Configuration features of EPMM. Ivanti has released emergency patches and advised organizations to apply them immediately to mitigate risks. However, the patches do not survive version upgrades, necessitating ongoing vigilance. The attack vector has been linked to a broader trend of rapid exploitation following vulnerability disclosures, raising concerns about the security of mobile device management systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (111)
Following this threat?
Track Cybersecurity and Infrastructure Security Agency and CVE-2025-20337 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…