International Cyber Digest[verified]@IntCyberDigestActive Exploitation
The tweet claims that Dutch agencies were compromised through two critical 0‑day vulnerabilities in Ivanti EPMM, indicating these CVEs are actively exploited.
watchTowr[verified]@watchtowrcyberGeneral
It references two pre‑authentication RCE vulnerabilities in Ivanti EPMM but offers no PoC, exploit details, or patch information, merely a link to a research page.
Harsh Jaiswal[verified]@rootxharshExploit
An exploit and PoC for CVE-2026-1731 have been released, with no mention of active exploitation or patching, and limited technical details about a bash‑script–based vulnerability.
watchTowr[verified]@watchtowrcyberDisclosure
WatchTowr has announced that Ivanti Endpoint Manager Mobile (EPMM) is affected by two unauthenticated RCE vulnerabilities (CVE-2026-1281 & CVE-2026-1340) and has advised clients to contact them for support.
blackorbird[verified]@blackorbirdActive Exploitation
Two critical zero‑day CVEs (CVE‑2026‑1281, CVE‑2026‑1340) in Ivanti Endpoint Manager Mobile are being actively exploited in the wild, allowing unauthenticated attackers to remotely execute arbitrary code and take full control of the MDM infrastructure.
Florian Roth ⚡️[verified]@cyb3ropsGeneral
The excerpt links to Ivanti’s analysis of CVE-2026-1281 and CVE-2026-1340 but does not provide PoC, exploit code, patch details, or in-depth technical data.
watchTowr[verified]@watchtowrcyberActive Exploitation
The tweet reports that when Ivanti disclosed the two EPMM RCE CVEs, active exploitation was already underway, and the author’s security solutions detected and auto‑mitigated the threats.
Costin Raiu[verified]@craiuActive Exploitation
The post announces that the Ivanti CVEs 2026‑1281 and 2026‑1340 are being actively exploited and have just been patched, with no PoC or exploit code disclosed.