Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical Ivanti EPMM Zero-Day Vulnerabilities Exploited in The Wild Targeting Corporate Networks

Two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) have been identified, posing significant threats to enterprise networks. These vulnerabilities, labelled as CVE-2026-1281 and CVE-2026-1340, allow unauthorized attackers to…

Two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) have been identified, posing significant threats to enterprise networks. These vulnerabilities, labelled as CVE-2026-1281 and CVE-2026-1340, allow unauthorized attackers to execute arbitrary code remotely without user credentials or interaction.

Organizations in the United States, Germany, Australia, and Canada have already been affected, with industries such as government, healthcare, manufacturing, professional services, and technology being particularly impacted. The vulnerabilities provide attackers with full control over mobile device management infrastructure, enabling the installation of malicious software and the establishment of unauthorized access.

Unit 42 has observed widespread automated exploitation attempts since the disclosure of these vulnerabilities in January 2026. The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-1281 to its Known Exploited Vulnerabilities Catalog due to its severity and ongoing exploitation.

Palo Alto Networks researchers have identified over 4,400 EPMM instances exposed on the internet via their Cortex Xpanse telemetry system. Attackers are rapidly transitioning from initial reconnaissance to deploying backdoors to maintain access, even after patches are applied.

Two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) have been identified, posing significant threats to enterprise networks.
Rachel Green · Thehackingpost

The vulnerabilities originate from unsafe bash script usage in legacy components managing URL rewriting in the Apache web server configuration. CVE-2026-1281 affects scripts for the In-House Application Distribution feature, while CVE-2026-1340 impacts the Android File Transfer mechanism.

Attackers have deployed various malware types to exploit vulnerable systems. Security researchers have observed the installation of lightweight JSP web shells in the server's web application directory, granting administrative control if the server operates with elevated privileges.

In some cases, attackers attempted to download the Nezha monitoring agent, targeting victims in China. Campaigns have also involved installing cryptominers or persistent backdoors on compromised devices. Additionally, sleep commands were used for reconnaissance to assess server vulnerabilities.

Advertisement

Ivanti has issued version-specific patches (RPM 12.x.0.x or RPM 12.x.1.x) that require no downtime and apply quickly. Organizations are advised to patch vulnerable systems promptly and review appliances for signs of prior exploitation. An Exploitation Detection script, developed with NCSC-NL, is available to help identify potential compromises.

Unit 42 advises adopting an assumed breach mentality and treating any detection of indicators as potential compromise with deeper persistence.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories