Ivanti has patched two critical zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM) product that are already being exploited, continuing a grim run of January security incidents for enterprise IT vendors. In January 2025, tens of thousands were urged to patch a Fortinet zero-day, while Ivanti customers were doing the same. There has been little change this year as Fortinet patches multiple single sign-on (SSO) flaws and Ivanti ships fixes for yet another pair of zero-days. Tracked as CVE-2026-1281 and CVE-2026-1340, both bugs affect Ivanti Endpoint Manager Mobile (EPMM). They're also both rated a near-maximum CVSS score of 9.8 and allow for unauthenticated remote code execution (RCE) – about as bad as it gets. The security shop said in its advisory: "We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure. "This vulnerability does not impact any other Ivanti products, including any cloud products, such as Ivanti Neurons for MDM. Ivanti Endpoint Manager (EPM) is a different product and also not impacted by these vulnerabilities. Customers using an Ivanti cloud product with Sentry are also not impacted by this vulnerability." These kinds of RCE bugs can lead to all sorts of nastiness. Lateral movement across a given organization's network, config changes, and attackers making themselves admin are all possible. The vendor warned that it could grant access to certain data too. Ivanti said that the types of informat...
January blues return as Ivanti coughs up exploited EPMM zero-days
The Register
·Connor Jones
·Published Jan 30, 2026
·Updated
Affected Software
1 affected component
Ivanti Endpoint Manager Mobile=all
Frequently Asked Questions
1
What vulnerabilities were disclosed in the article?
The article discusses two critical zero-day vulnerabilities in Ivanti's Endpoint Manager Mobile (EPMM) product.
2
How severe are the vulnerabilities mentioned?
The vulnerabilities are classified as critical and are already being actively exploited.
3
Which product is affected by the zero-day vulnerabilities?
The affected product is Ivanti Endpoint Manager Mobile.
4
What measures has Ivanti taken regarding the vulnerabilities?
Ivanti has released patches for the critical zero-day vulnerabilities in EPMM.
5
When were the vulnerabilities disclosed?
The vulnerabilities were disclosed in January 2026.