CyberzSOC

Publication detail
← Back to advisories & guidance

2026-001: Critical vulnerabilities in Ivanti EPMM ↗ source

January 30, 2026 CERT-EU Advisory

Summary

An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device. One of these vulnerabilities have been exploited in a The vulnerability CVE-2026-1281, with a CVSS score of 9.8, is a code injection vulnerability in Ivanti Endpoint Manager Mobile. The vulnerability CVE-2026-1340, with a CVSS score of 9.8, is a code injection vulnerability in Ivanti Endpoint Manager Mobile. The following versions of Ivanti’s Endpoint Manager Mobile (EPMM) are affected: CERT-EU recommends securing forensic evidence to detect any signs of exploitation. CERTEU also recommends following the vendor’s guidance to apply the hotfix (i.e. RPM 12.x.0 or RPM 12.x.1) on vulnerable appliances.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-1281 9.8 Critical Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execu…
CVE-2026-1340 9.8 Critical Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execu…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.