CVE-2026-1281: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Other sources
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Ivanti Endpoint Manager Mobile (EPMM)from your environment.Discontinue use of the product if mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1281?
CVE-2026-1281 is classified as a critical vulnerability due to its potential for unauthenticated remote code execution.
How do I fix CVE-2026-1281?
To fix CVE-2026-1281, update your Ivanti Endpoint Manager Mobile to the latest version that addresses this vulnerability.
What versions of Ivanti Endpoint Manager Mobile are affected by CVE-2026-1281?
CVE-2026-1281 affects Ivanti Endpoint Manager Mobile versions up to 12.7.0.0 inclusive, including specific version numbers 12.5.0.0 to 12.7.0.0.
What are the risks of not addressing CVE-2026-1281?
Not addressing CVE-2026-1281 poses significant risks including unauthorized remote code execution that can compromise systems and data.
Can CVE-2026-1281 be exploited remotely?
Yes, CVE-2026-1281 allows attackers to achieve unauthenticated remote code execution, making it exploitable over a network.