Site icon TheCyberThrone

Ivanti EPMM Zero-Days CVE-2026-1281 & CVE-2026-1340

Advertisements

Ivanti has issued a critical security advisory for two zero-day remote code execution (RCE) vulnerabilities in Endpoint Manager Mobile (EPMM), actively exploited in the wild. CVE-2026-1281 joined CISA’s Known Exploited Vulnerabilities (KEV) catalog on January 29, 2026, with federal deadlines looming.

Vulnerability Breakdown

These flaws target EPMM’s In-House Application Distribution and Android File Transfer features, enabling unauthenticated attackers to inject code and seize appliance control.

Attackers can extract managed device data, deploy webshells, and pivot laterally in enterprise networks.

Scope and Impact

Detection and IOCs

Scan Apache logs for suspicious 404s on valid endpoints (legit requests return 200).
Key signs of compromise:

Remediation Roadmap

  1. Patch Immediately: Install Ivanti RPM updates after validation.
  2. Run Tools: Use official integrity checker and compromise scanners.
  3. Hunt & Isolate: Review logs, segment endpoints, and monitor anomalies.

Ivanti’s string of KEV entries underscores the need for rapid MDM patching—act now to safeguard mobile fleets.

Exit mobile version