Widespread Exploitation of Ivanti EPMM Vulnerability CVE-2026-1281

Widespread Exploitation of Ivanti EPMM Vulnerability CVE-2026-1281

First seen 12 Feb 2026, 21:16 UTC CybersecuritydiveHelpnetsecurity 22.0

Article Content

Browse articles
ThreatCluster

Following the disclosure of CVE-2026-1281, a critical pre-authentication vulnerability in Ivanti EPMM, there has been a significant increase in exploitation attempts. Security researchers have reported targeting activities affecting various organizations, including government entities, with over 600 individual IP addresses involved in these attacks.

Timeline

2026-02-10
Cybersecuritydive article reports widespread exploitation attempts
2026-02-11
Helpnetsecurity article warns of sleeper webshells following CVE disclosure
2026-02-11
CVE-2026-1281 disclosed