Critical Ivanti EPMM Zero-Day Vulnerabilities Exploited in The Wild Targeting Corporate Networks
Two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) have been identified, posing significant threats to enterprise networks. These vulnerabilities, labelled as CVE-2026-1281 and CVE-2026-1340, allow unauthorized attackers to…
Two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) have been identified, posing significant threats to enterprise networks. These vulnerabilities, labelled as CVE-2026-1281 and CVE-2026-1340, allow unauthorized attackers to execute arbitrary code remotely without user credentials or interaction.
Organizations in the United States, Germany, Australia, and Canada have already been affected, with industries such as government, healthcare, manufacturing, professional services, and technology being particularly impacted. The vulnerabilities provide attackers with full control over mobile device management infrastructure, enabling the installation of malicious software and the establishment of unauthorized access.
Unit 42 has observed widespread automated exploitation attempts since the disclosure of these vulnerabilities in January 2026. The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-1281 to its Known Exploited Vulnerabilities Catalog due to its severity and ongoing exploitation.
Palo Alto Networks researchers have identified over 4,400 EPMM instances exposed on the internet via their Cortex Xpanse telemetry system. Attackers are rapidly transitioning from initial reconnaissance to deploying backdoors to maintain access, even after patches are applied.
Two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) have been identified, posing significant threats to enterprise networks.
The vulnerabilities originate from unsafe bash script usage in legacy components managing URL rewriting in the Apache web server configuration. CVE-2026-1281 affects scripts for the In-House Application Distribution feature, while CVE-2026-1340 impacts the Android File Transfer mechanism.
Attackers have deployed various malware types to exploit vulnerable systems. Security researchers have observed the installation of lightweight JSP web shells in the server's web application directory, granting administrative control if the server operates with elevated privileges.
In some cases, attackers attempted to download the Nezha monitoring agent, targeting victims in China. Campaigns have also involved installing cryptominers or persistent backdoors on compromised devices. Additionally, sleep commands were used for reconnaissance to assess server vulnerabilities.
Ivanti has issued version-specific patches (RPM 12.x.0.x or RPM 12.x.1.x) that require no downtime and apply quickly. Organizations are advised to patch vulnerable systems promptly and review appliances for signs of prior exploitation. An Exploitation Detection script, developed with NCSC-NL, is available to help identify potential compromises.
Unit 42 advises adopting an assumed breach mentality and treating any detection of indicators as potential compromise with deeper persistence.
Based on reporting by Cyber Security News.
