• News/
  • https://www.bleepingcomputer.com/news/security/ivanti-warns-of-two-epmm-flaws-exploited-in-zero-day-attacks/

Ivanti warns of two EPMM flaws exploited in zero-day attacks

BleepingComputer
·
Lawrence Abrams
·
Published Jan 29, 2026
·
Updated

Ivanti has disclosed two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1281 and CVE-2026-1340, that were exploited in zero-day attacks. The flaws are code-injection vulnerabilities that allow remote attackers to execute arbitrary code on vulnerable devices without authentication. Both vulnerabilities have a CVSS score of 9.8 and are rated as critical. "We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure," warns Ivanti. Ivanti has released RPM scripts to mitigate the vulnerabilities for affected EPMM versions: The company says there is no downtime required to apply the patches and that there is no functional impact, so it is strongly advised to apply them as soon as possible. However, the company does warn that the hotfixes do not survive a version upgrade and must be reapplied if the appliance is upgraded before a permanent fix is available. The vulnerabilities will be permanently fixed in EPMM version 12.8.0.0, which will be released later in Q1 2026. Ivanti says successful exploitation allows attackers to execute arbitrary code on the EPMM appliance, allowing attackers access to a wide range of information stored on the platform. This information includes administrator and user names, usernames, and email addresses, as well as information about managed mobile devices such as phone numbers, IP addresses, installed applications, and device identifiers like IMEI and MAC address...

Read full article

Affected Software

1 affected component
Ivanti Endpoint Manager Mobile>=12.7.0.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) that were exploited in zero-day attacks.

2

What vulnerabilities are reported in the article?

The vulnerabilities mentioned are tracked as CVE-2026-1281 and CVE-2026-1340, both of which are code-injection flaws.

3

What security implications are discussed in the article?

The article highlights that these vulnerabilities could allow remote attackers to exploit the system, potentially leading to unauthorized access.

4

What products or software are affected?

The affected software is Ivanti Endpoint Manager Mobile, specifically versions starting from 12.7.0.0.

5

Has Ivanti provided a fix or mitigation for these vulnerabilities?

The article does not specify if Ivanti has released a fix or mitigation steps for the reported vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203