CVE-2026-1340: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Other sources
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of Ivanti Endpoint Manager Mobile (EPMM) if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1340?
CVE-2026-1340 has been classified with a critical severity rating due to the potential for unauthenticated remote code execution.
How do I fix CVE-2026-1340?
To remediate CVE-2026-1340, update your Ivanti Endpoint Manager Mobile software to the latest patched version as recommended by Ivanti.
Who is affected by CVE-2026-1340?
Users and organizations utilizing Ivanti Endpoint Manager Mobile are at risk from CVE-2026-1340.
What type of vulnerability is CVE-2026-1340?
CVE-2026-1340 is classified as a code injection vulnerability that allows for remote code execution.
Can CVE-2026-1340 be exploited without authentication?
Yes, CVE-2026-1340 can be exploited by attackers without requiring authentication.