Single IP Dominates Exploitation Campaign Attacking Ivanti EPMM with RCE Vulnerability
A critical remote code execution (RCE) vulnerability in Ivanti Endpoint Manager Mobile (EPMM), identified as CVE-2026-1281 , is currently undergoing significant exploitation. Data from GreyNoise indicate that 83% of observed attacks originate from a…
A critical remote code execution (RCE) vulnerability in Ivanti Endpoint Manager Mobile (EPMM), identified as CVE-2026-1281 , is currently undergoing significant exploitation. Data from GreyNoise indicate that 83% of observed attacks originate from a single IP address: 193[.]24[.]123[.]42.
This IP address is registered to PROSPERO OOO (AS200593) and classified as "bulletproof" hosting. Notably, this IP was absent in many early indicators of compromise shared with security defenders.
Two Critical Vulnerabilities Under Active Attack
The vulnerability CVE-2026-1281 (CVSS 9.8) permits unauthenticated attackers to execute system commands via Bash arithmetic expansion within backend file-delivery scripts.
Another vulnerability, CVE-2026-1340, also with a CVSS score of 9.8, allows similar code execution in a different EPMM component.
Ivanti released an advisory on January 29. Following this, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-1281 to its Known Exploited Vulnerabilities catalog.
Data from GreyNoise indicate that 83% of observed attacks originate from a single IP address: 193[.]24[.]123[.]42.
Dutch authorities confirmed breaches at the Dutch Data Protection Authority (AP) and the Council for the Judiciary (RVDR), indicating pre-existing attacks before organizations applied patches.
Between February 1 and 9, GreyNoise recorded 417 exploitation sessions from eight different IPs. On February 8 alone, there were 269 sessions, approximately 13 times the previous daily average.
The primary IP, 193[.]24[.]123[.]42, is associated with attacks on Oracle WebLogic Server, GNU Inetutils telnetd , and GLPI. The use of numerous user-agent strings suggests automated mass exploitation.
Some commonly shared indicators of compromise did not align with Ivanti exploitation data. For instance, Windscribe VPN exit nodes on M247 infrastructure generated significant traffic, but none targeted Ivanti EPMM.
Another indicator pointed to a residential router involved in limited activity. Organizations blocking only these VPN or residential IPs, without restricting AS200593, may have overlooked the primary threat.
Approximately 85% of the payloads utilized DNS callbacks to verify code execution, rather than immediately deploying malware. This behavior aligns with initial access broker tactics .
Reports also mention "sleeper" webshells located at /mifs/403.jsp, which remain inactive until triggered. Consequently, even patched systems might remain compromised if attackers accessed them before the vulnerabilities were addressed.
Based on reporting by Cyber Security News.
