Active Exploitation
#threatreport #HighCompleteness
Mass exploitation of CVE-2026-1281 and CVE-2026-1340 in Ivanti EPMM | 03-03-2026
Source: https://github.security.telekom.com/2026/03/ivanti-CVE-2026-1281-exploitation.html
Key details below ↓
💀Threats:
Ncat_tool, Credential_harvesting_technique, Nezha_tool,
🎯Victims: State and local government, Healthcare, Manufacturing, Professional services, Legal services, High technology
🏭Industry: Healthcare, Government
🌐Geo: China, Germany, Australia, German, Canada
🔓CVEs: CVE-2026-1281 \[[Vulners](https://vulners.com/cve/CVE-2026-1281)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- ivanti endpoint_manager_mobile (le12.5.0.0, 12.5.1.0, 12.6.0.0, 12.6.1.0, 12.7.0.0)
CVE-2023-35078 \[[Vulners](https://vulners.com/cve/CVE-2023-35078)]
- CVSS V3.1: *10.0*,
- Vulners: Exploitation: True
Soft:
- ivanti endpoint_manager_mobile (<11.8.1.1, <11.9.1.1, <11.10.0.2)
CVE-2026-1340 \[[Vulners](https://vulners.com/cve/CVE-2026-1340)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- ivanti endpoint_manager_mobile (le12.7.0.0)
📚TTPs:
⚔️Tactics: 2
🛠️Technics: 0
🤖LLM extracted TTPs:`
T1027, T1036, T1046, T1059.004, T1059.009, T1070.004, T1105, T1140, T1190, T1552, ...
🧨IOCs:
- File: 7
- IP: 211
- Url: 31
- Hash: 1
- Domain: 3
💽Software: Ivanti EPMM, Ivanti, RPORT, curl, mysql
🔢Algorithms: lzma, base64, sha256
🔠Functions: getMethod, getClass, getParameter, getClassLoader
📜Programming Languages: python, java
#threatreport:
In early 2026, significant threat activity was reported concerning two recently disclosed critical zero-day vulnerabilities in Ivanti's mobile device management platform, identified as CVE-2026-1281 and CVE-2026-1340. Both vulnerabilities, which receive a CVSS rating of 9.8, allow unauthenticated remote code execution (RCE), making Ivanti Endpoint Manager Mobile (EPMM) appliances prime targets for cyber exploitation. The exploit’s mechanism involves the unsafe handling of attacker-controlled input through a server-side Bash script in an internet-exposed EPMM web endpoint, enabling attackers to execute arbitrary commands without requiring authentication.
Following the disclosure by Ivanti on January 29, 2026, the German Federal Office for Information Security (BSI) highlighted ongoing exploitation attempts and advised organizations to adopt enhanced detection measures. The analysis revealed a variety of exploitation patterns, including initial exploitation through crafted HTTP requests targeting vulnerable endpoints, which validated RCE through repeated DNS lookups to confirm successful command execution.
Evidence gathered during investigations indicated that attackers deployed webshells in directories associated with Tomcat web applications. Specifically, they targeted '403.jsp' to append malicious Base64-decoded Java bytecode, enabling in-memory class loader capabilities. Additionally, logs showed attempts to manipulate file permissions to enhance control over compromised environments. The presence of reverse shell attempts using tools like 'nc' and 'ncat' suggests they aimed for interactive access.
Reports indicated activities related to loading secondary payloads, including a Base64-encoded ELF binary malware aimed at facilitating command and control operations. Specific database export commands targeting sensitive Ivanti user data signify attempts at credential harvesting, indicating a well-planned strategy for data exfiltration as well as lateral movement within affected networks.
The challenges escalated as multiple actors engaged in opportunistic exploitation, creating a noisy threat landscape. They shifted from scanning for vulnerable devices to more sophisticated actions, including establishing dormant backdoors and deploying secondary malware, indicative of a persistent approach to maintain long-term access. Notably, reconnaissance activities were linked to commands injected to measure server vulnerabilities.
As exploitation attempts rapidly spread across various sectors, particularly in the U.S., Germany, and Australia, security advisories called for immediate monitoring and response across networks, as organizations continued to face risks despite applying patches. Various indicators of compromise were associated with these threats, including altered file names typical of webshell deployment and suspicious data traffic. The BSI cautioned that even successfully patched systems should be considered compromised, advocating for broad network oversight to mitigate further risks stemming from these significant vulnerabilities.
Post summary
The report documents widespread, active exploitation of two critical Ivanti EPMM zero‑day CVEs, detailing Remote Code Execution via Bash scripts and reverse shell techniques, with confirmed real‑world attacks across multiple sectors and ongoing advisory efforts.