Related Threat Clusters
-
Critical Ivanti EPMM Vulnerabilities Under Active Exploitation
Two critical vulnerabilities in Ivanti's Endpoint Manager Mobile (EPMM), CVE-2026-1281 and CVE-2026-1340, have been actively exploited in the wild, allowing unauthenticated remote code execution (RCE) with a CVSS score…
64 articles · Updated January 29, 2026 -
Critical Vulnerabilities in Ivanti EPMM Expose Systems to Remote Attacks
Two critical vulnerabilities (CVE-2026-5787 and CVE-2026-5788) were disclosed in Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1. CVE-2026-5787 allows attackers to impersonate Sentry hosts and obtain…
2 articles · Updated May 8, 2026 -
Active Exploitation of Vulnerabilities in Ivanti and SolarWinds Products
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation of vulnerabilities in Ivanti Endpoint Manager, SolarWinds Web Help Desk, and VMware Workspace ONE. The…
12 articles · Updated March 10, 2026 -
Multiple Cybersecurity Incidents and Vulnerabilities Reported in February 2026
In February 2026, various cybersecurity incidents were reported, including the exploitation of Ivanti EPMM vulnerabilities linked to a single IP address and the discovery of malicious packages by the Lazarus group in…
52 articles · Updated February 12, 2026 -
Surge in Exploitation of Ivanti EPMM Zero-Day Vulnerabilities
Security researchers report a rise in exploitation of critical Ivanti EPMM zero-day vulnerabilities. These vulnerabilities are being used to deliver shells, conduct reconnaissance, and download malware, primarily…
2 articles · Updated February 19, 2026 -
OpenAI Enhances ChatGPT Security; Ivanti EPMM Backdoors Exploited
OpenAI has implemented two new security features in ChatGPT to prevent prompt injection attacks. Meanwhile, threat actors have exploited two Ivanti zero-day vulnerabilities, CVE-2026-1281 and CVE-2026-1340, to deploy…
3 articles · Updated February 18, 2026 -
Widespread Exploitation of Ivanti EPMM Vulnerability CVE-2026-1281
Following the disclosure of CVE-2026-1281, a critical pre-authentication vulnerability in Ivanti EPMM, there has been a significant increase in exploitation attempts. Security researchers have reported targeting…
2 articles · Updated February 11, 2026
Recent Intelligence Reports
- CVE-2026-5788 — nvd.nist.gov · May 8, 2026
- Endpoint Manager CVEs and Security Vulnerabilities — App.Opencve · March 10, 2026
- Critical Ivanti EPMM Zero-Day Vulnerabilities Exploited in the Wild, Targeting Corporate Networks — Gbhackers · February 18, 2026
- Attackers Deploy Dormant Backdoors in Ivanti EPMM to Bypass Patching of Latest 0 — Thecyberexpress · February 18, 2026
- 83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure — Thehackernews · February 12, 2026
- Ivanti EPMM exploitation: Researchers warn of "sleeper" webshells — Helpnetsecurity · February 11, 2026
- Ivanti EPMM exploitation widespread as governments, others targeted — Cybersecuritydive · February 10, 2026
- Hackers Actively Exploiting Ivanti EPMM Devices to Deploy Dormant Backdoors — Cyberpress · February 10, 2026