Critical Ivanti Endpoint Manager 0-day RCE Vulnerabilities Actively Exploited in Attacks
Two critical code-injection vulnerabilities have been identified in Ivanti's Endpoint Manager Mobile (EPMM) platform, which are being actively exploited. The security issues, tracked as CVE-2026-1281 and CVE-2026-1340, allow unauthenticated attackers to…
Two critical code-injection vulnerabilities have been identified in Ivanti's Endpoint Manager Mobile (EPMM) platform, which are being actively exploited. The security issues, tracked as CVE-2026-1281 and CVE-2026-1340, allow unauthenticated attackers to execute arbitrary code remotely on affected systems.
These vulnerabilities have a CVSS severity score of 9.8 and impact multiple EPMM versions, including 12.5.0.0, 12.6.0.0, and 12.7.0.0. Ivanti's security advisory, dated Thu, Jan 29, 2026, indicates that a limited number of customer environments have been compromised.
Both vulnerabilities result from code-injection weaknesses (CWE-94) that can be exploited without authentication or user interaction. The attack vector is network-based and low-complexity, allowing threat actors to remotely compromise vulnerable EPMM instances with minimal effort.
Successful exploitation provides attackers complete control over the confidentiality, integrity, and availability of affected systems.
CVE Number Description CVSS Score CVSS Vector CWE
Two critical code-injection vulnerabilities have been identified in Ivanti's Endpoint Manager Mobile (EPMM) platform, which are being actively exploited.
CVE-2026-1281 Code injection enabling unauthenticated RCE 9.8 (Critical) AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CWE-94
CVE-2026-1340 Code injection enabling unauthenticated RCE 9.8 (Critical) AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CWE-94
Ivanti has released version-specific RPM patches to mitigate these security flaws. The permanent fix is scheduled for version 12.8.0.0, expected in Q1 2026. The temporary patches do not require system downtime and maintain feature functionality. However, administrators must reapply the RPM script after version upgrades.
Organizations running EPMM should promptly apply the version-specific RPM patches available through Ivanti's support portal. Customers using versions 12.5.0.x through 12.7.0.x require RPM 12.x.0.x, while those on 12.5.1.0 or 12.6.1.0 should deploy RPM 12.x.1.x. Only one patch is necessary based on the deployed version.
Ivanti recommends that security-conscious organizations consider rebuilding EPMM environments and migrating data to replacement systems as a conservative remediation approach. While technical analysis documentation with forensic guidance is provided, reliable indicators of compromise are not yet available as investigations continue.
Other Ivanti products, including Endpoint Manager (EPM), Neurons for MDM, and Sentry appliances, are not impacted by these vulnerabilities.
Based on reporting by Cyber Security News.
