Ivanti has disclosed two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1281 and CVE-2026-1340, that were exploited in zero-day attacks. The flaws are code-injection vulnerabilities that allow remote attackers to execute arbitrary code on vulnerable devices without authentication. Both vulnerabilities have a CVSS score of 9.8 and are rated as critical. "We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure," warns Ivanti. Ivanti has released RPM scripts to mitigate the vulnerabilities for affected EPMM versions: The company says there is no downtime required to apply the patches and that there is no functional impact, so it is strongly advised to apply them as soon as possible. However, the company does warn that the hotfixes do not survive a version upgrade and must be reapplied if the appliance is upgraded before a permanent fix is available. The vulnerabilities will be permanently fixed in EPMM version 12.8.0.0, which will be released later in Q1 2026. Ivanti says successful exploitation allows attackers to execute arbitrary code on the EPMM appliance, allowing attackers access to a wide range of information stored on the platform. This information includes administrator and user names, usernames, and email addresses, as well as information about managed mobile devices such as phone numbers, IP addresses, installed applications, and device identifiers like IMEI and MAC address...
Ivanti warns of two EPMM flaws exploited in zero-day attacks
BleepingComputer
·Lawrence Abrams
·Published Jan 29, 2026
·Updated
Affected Software
1 affected component
Ivanti Endpoint Manager Mobile>=12.7.0.0
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) that were exploited in zero-day attacks.
2
What vulnerabilities are reported in the article?
The vulnerabilities mentioned are tracked as CVE-2026-1281 and CVE-2026-1340, both of which are code-injection flaws.
3
What security implications are discussed in the article?
The article highlights that these vulnerabilities could allow remote attackers to exploit the system, potentially leading to unauthorized access.
4
What products or software are affected?
The affected software is Ivanti Endpoint Manager Mobile, specifically versions starting from 12.7.0.0.
5
Has Ivanti provided a fix or mitigation for these vulnerabilities?
The article does not specify if Ivanti has released a fix or mitigation steps for the reported vulnerabilities.