CVE-2026-1281Active Exploitation(ivanti / endpoint_manager_mobile)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 66 mentions and remains active

Immediate actions

  • Patch ivanti endpoint_manager_mobile systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-01. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager_mobile

Threat summary

  • Active exploitation appears in 198 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 284 mentions across 50 observed days

What's happening

  • Active exploitation reported across 198 signals
  • Exploit tool or code specified in 10 signals
  • PoC mentioned or linked in 21 signals
  • Patch or workaround mentioned in 110 signals
  • Technical details provided in 164 signals
  • Disclosure: 38 classified signals
  • Peaked 48d ago at 66 mentions (2026-01-30); latest day: 1
  • 284 total mentions across 50 days

Affected systems

Vendors
Products
endpoint_manager_mobile

4 versions affected across 1 product

Deep dive

Activity timeline284 mentions / 50d
017335066Mentions · 2026-01-29: 15Mentions · 2026-01-30: 66Mentions · 2026-01-31: 12Mentions · 2026-02-01: 6Mentions · 2026-02-02: 21Mentions · 2026-02-03: 11Mentions · 2026-02-04: 7Mentions · 2026-02-05: 4Mentions · 2026-02-06: 1Mentions · 2026-02-07: 3Mentions · 2026-02-09: 9Mentions · 2026-02-10: 17Mentions · 2026-02-11: 10Mentions · 2026-02-12: 13Mentions · 2026-02-13: 3Mentions · 2026-02-14: 2Mentions · 2026-02-16: 2Mentions · 2026-02-17: 5Mentions · 2026-02-18: 20Mentions · 2026-02-19: 6Mentions · 2026-02-20: 2Mentions · 2026-02-23: 3Mentions · 2026-02-24: 2Mentions · 2026-02-25: 3Mentions · 2026-02-26: 2Mentions · 2026-02-27: 2Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-06: 4Mentions · 2026-03-07: 1Mentions · 2026-03-08: 1Mentions · 2026-03-10: 1Mentions · 2026-03-18: 1Mentions · 2026-03-20: 1Mentions · 2026-03-25: 1Mentions · 2026-03-26: 4Mentions · 2026-03-27: 1Mentions · 2026-03-29: 2Mentions · 2026-04-02: 1Mentions · 2026-04-06: 1Mentions · 2026-04-08: 2Mentions · 2026-04-09: 2Mentions · 2026-04-11: 1Mentions · 2026-05-04: 3Mentions · 2026-05-05: 1Mentions · 2026-05-08: 3Mentions · 2026-05-11: 1Mentions · 2026-06-25: 1Mentions · 2026-07-08: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-01-30: 2PoC Mentioned / Linked · 2026-02-01: 1PoC Mentioned / Linked · 2026-02-02: 2PoC Mentioned / Linked · 2026-02-04: 1PoC Mentioned / Linked · 2026-02-09: 1PoC Mentioned / Linked · 2026-02-10: 3PoC Mentioned / Linked · 2026-02-11: 1PoC Mentioned / Linked · 2026-02-12: 2PoC Mentioned / Linked · 2026-02-16: 2PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-03-04: 1PoC Mentioned / Linked · 2026-03-08: 1PoC Mentioned / Linked · 2026-03-26: 3Exploit Tool / Code · 2026-01-30: 1Exploit Tool / Code · 2026-02-09: 1Exploit Tool / Code · 2026-02-10: 2Exploit Tool / Code · 2026-02-18: 2Exploit Tool / Code · 2026-02-25: 1Exploit Tool / Code · 2026-03-26: 2Exploit Tool / Code · 2026-04-02: 1Active Exploitation · 2026-01-29: 9Active Exploitation · 2026-01-30: 45Active Exploitation · 2026-01-31: 9Active Exploitation · 2026-02-01: 2Active Exploitation · 2026-02-02: 13Active Exploitation · 2026-02-03: 6Active Exploitation · 2026-02-04: 6Active Exploitation · 2026-02-05: 3Active Exploitation · 2026-02-07: 1Active Exploitation · 2026-02-09: 8Active Exploitation · 2026-02-10: 10Active Exploitation · 2026-02-11: 9Active Exploitation · 2026-02-12: 11Active Exploitation · 2026-02-13: 2Active Exploitation · 2026-02-14: 2Active Exploitation · 2026-02-16: 2Active Exploitation · 2026-02-17: 5Active Exploitation · 2026-02-18: 16Active Exploitation · 2026-02-19: 3Active Exploitation · 2026-02-20: 1Active Exploitation · 2026-02-23: 2Active Exploitation · 2026-02-24: 2Active Exploitation · 2026-02-25: 2Active Exploitation · 2026-02-26: 2Active Exploitation · 2026-02-27: 2Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-06: 2Active Exploitation · 2026-03-07: 1Active Exploitation · 2026-03-08: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-25: 1Active Exploitation · 2026-03-26: 3Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-03-29: 1Active Exploitation · 2026-04-02: 1Active Exploitation · 2026-04-06: 1Active Exploitation · 2026-04-08: 2Active Exploitation · 2026-04-09: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-05-04: 2Active Exploitation · 2026-05-08: 3Active Exploitation · 2026-07-08: 1Patch / Workaround · 2026-01-29: 6Patch / Workaround · 2026-01-30: 36Patch / Workaround · 2026-01-31: 8Patch / Workaround · 2026-02-01: 1Patch / Workaround · 2026-02-02: 6Patch / Workaround · 2026-02-03: 4Patch / Workaround · 2026-02-05: 3Patch / Workaround · 2026-02-09: 3Patch / Workaround · 2026-02-10: 3Patch / Workaround · 2026-02-11: 5Patch / Workaround · 2026-02-12: 7Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-02-16: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-02-18: 7Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-23: 2Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-04-08: 2Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-05-08: 3Patch / Workaround · 2026-07-08: 1Technical Details · 2026-01-29: 9Technical Details · 2026-01-30: 45Technical Details · 2026-01-31: 7Technical Details · 2026-02-01: 2Technical Details · 2026-02-02: 12Technical Details · 2026-02-03: 6Technical Details · 2026-02-04: 2Technical Details · 2026-02-05: 3Technical Details · 2026-02-07: 1Technical Details · 2026-02-09: 5Technical Details · 2026-02-10: 8Technical Details · 2026-02-11: 7Technical Details · 2026-02-12: 6Technical Details · 2026-02-13: 1Technical Details · 2026-02-14: 2Technical Details · 2026-02-16: 2Technical Details · 2026-02-17: 3Technical Details · 2026-02-18: 9Technical Details · 2026-02-19: 4Technical Details · 2026-02-20: 2Technical Details · 2026-02-23: 2Technical Details · 2026-02-24: 2Technical Details · 2026-02-25: 3Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-08: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-26: 2Technical Details · 2026-04-02: 1Technical Details · 2026-04-08: 2Technical Details · 2026-04-09: 2Technical Details · 2026-04-11: 1Technical Details · 2026-05-08: 3Technical Details · 2026-06-25: 1Technical Details · 2026-07-08: 1Technical Details · 2026-09-15: 101-2902-0302-0902-1402-2002-2703-0803-2604-0805-0809-15
Signal classification6 categories
Active Exploitation
17059.9%
Disclosure
3813.4%
Patch
3813.4%
General
3211.3%
Exploit
31.1%
PoC
31.1%
Referenced assets226 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-2915
Active Exploitation8Disclosure4General1Patch2
2026-01-3066
Active Exploitation30Disclosure11Exploit1General6Patch18
2026-01-3112
Active Exploitation7Disclosure1General1Patch3
2026-02-016
Active Exploitation2Disclosure2General1PoC1
2026-02-0221
Active Exploitation11Disclosure4General3Patch3
2026-02-0311
Active Exploitation6Disclosure2General2Patch1
2026-02-047
Active Exploitation6General1
2026-02-054
Active Exploitation3Patch1
2026-02-061
General1
2026-02-073
Active Exploitation1General1Patch1
2026-02-099
Active Exploitation7General1Patch1
2026-02-1017
Active Exploitation9Disclosure2Exploit2General4
2026-02-1110
Active Exploitation7General1Patch2
2026-02-1213
Active Exploitation11Disclosure1PoC1
2026-02-133
Active Exploitation2General1
2026-02-142
Active Exploitation2
2026-02-162
Active Exploitation1Patch1
2026-02-175
Active Exploitation5
2026-02-1820
Active Exploitation14General2Patch4
2026-02-196
Active Exploitation3Disclosure2PoC1
2026-02-202
Active Exploitation1Disclosure1
2026-02-233
Active Exploitation2General1
2026-02-242
Active Exploitation2
2026-02-253
Active Exploitation2Disclosure1
2026-02-262
Active Exploitation2
2026-02-272
Active Exploitation2
2026-03-031
Disclosure1
2026-03-041
Active Exploitation1
2026-03-064
Active Exploitation2Disclosure2
2026-03-071
Active Exploitation1
2026-03-081
Active Exploitation1
2026-03-101
Active Exploitation1
2026-03-181
General1
2026-03-201
Active Exploitation1
2026-03-251
Active Exploitation1
2026-03-264
Active Exploitation3Disclosure1
2026-03-271
Active Exploitation1
2026-03-292
Active Exploitation1Disclosure1
2026-04-021
Active Exploitation1
2026-04-061
Active Exploitation1
2026-04-082
Active Exploitation2
2026-04-092
Active Exploitation1General1
2026-04-111
Active Exploitation1
2026-05-043
Active Exploitation2General1
2026-05-051
General1
2026-05-083
Active Exploitation2Patch1
2026-05-111
Disclosure1
2026-06-251
General1
2026-07-081
Active Exploitation1
2026-09-151
Disclosure1
Full discourse20 posts
  • International Cyber Digest@IntCyberDigest
    Active Exploitation

    ❗️ Leaked: Dutch Prison Agency (DJI) hacked This breach, and those of the Dutch Data Protection Authority, the Council for the Judiciary, the European Commission and Finland’s government, all trace back to two critical 0-day vulnerabilities in Ivanti EPMM: CVE-2026-1281 and CVE-2026-1340.

    Post summary

    The tweet claims that Dutch agencies were compromised through two critical 0‑day vulnerabilities in Ivanti EPMM, indicating these CVEs are actively exploited.

    135362947024.1K
    92.7K followersView on X
  • watchTowr@watchtowrcyber
    General

    Someone knows Bash disgustingly well, and we love it. Here's our analysis of the Ivanti EPMM Pre-Auth RCE vulnerabilities - CVE-2026-1281 & CVE-2026-1340. This research fuels our technology, enabling our clients to accurately determine their exposure. https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340

    Post summary

    It references two pre‑authentication RCE vulnerabilities in Ivanti EPMM but offers no PoC, exploit details, or patch information, merely a link to a research page.

    870622712031.2K
    11.0K followersView on X
  • Harsh Jaiswal@rootxharsh
    Exploit

    The exploit for CVE-2026-1731 is out. The APT of CVE-2026-1281 missed a major target 😅. Props to watchTowr for the blog on it. The moment I read it, my instinct said there had to be a variant in remote support, given how heavily it relies on bash scripts. @HacktronAI did the rest. Literally gave me PoC in hand. (Vibe hacking?) What surprised me was that I didn’t know this bash quirk earlier, even though I’d already run into a similar quirk in another language. Consider this a reminder: read the blogs. Always.

    Post summary

    An exploit and PoC for CVE-2026-1731 have been released, with no mention of active exploitation or patching, and limited technical details about a bash‑script–based vulnerability.

    1130974514.6K
    22.1K followersView on X
  • Defused@DefusedCyber
    General

    🚨 We are seeing pre-exploitation recon for Ivanti CVE-2026-1281/CVE-2026-1340 since the early AM hours today Attackers can probe the /mifs/c/appstore path to determine if the target is vulnerable to CVE-2026-1281 / CVE-2026-1340 No public POC exists as of right now. https://t.co/AVW15ZnYda

    Post summary

    The tweet reports ongoing pre-exploitation recon activity against Ivanti CVE‑2026‑1281/CVE‑2026‑1340, noting no public PoC yet and providing the specific path used for reconnaissance.

    4161982611.5K
    6.0K followersView on X
  • watchTowr@watchtowrcyber
    Disclosure

    🚨 The watchTowr team is rapidly reacting to CVE-2026-1281 & CVE-2026-1340 - unauth RCE vulnerabilities within Ivanti's Endpoint Manager Mobile (EPMM). Active watchTowr Platform clients have been made aware of their exposure - reach out via the watchTowr website for support. https://t.co/wkYOHloPPJ

    Post summary

    WatchTowr has announced that Ivanti Endpoint Manager Mobile (EPMM) is affected by two unauthenticated RCE vulnerabilities (CVE-2026-1281 & CVE-2026-1340) and has advised clients to contact them for support.

    3231802211.2K
    11.0K followersView on X
  • Unit 42@Unit42_Intel
    Active Exploitation

    We detail exploitation of zero-day vulnerabilities CVE-2026-1281 and CVE-2026-1340 discovered in Ivanti EPMM. A global exploitation campaign is affecting multiple critical sectors: https://bit.ly/4aAho7Q https://t.co/BBts3tDQRl

    Post summary

    The tweet reports a global exploitation campaign targeting Ivanti EPMM zero‑day vulnerabilities CVE-2026-1281 and CVE-2026-1340, indicating active attacks across multiple critical sectors.

    1322691917.7K
    66.5K followersView on X
  • blackorbird@blackorbird
    Active Exploitation

    Two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) affecting Ivanti Endpoint Manager Mobile (EPMM) are being actively exploited in the wild, affecting enterprise mobile fleets and corporate networks. These vulnerabilities allow unauthenticated attackers to remotely execute arbitrary code on target servers, granting them full control over mobile device management (MDM) infrastructure without requiring user interaction or credentials. https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/

    Post summary

    Two critical zero‑day CVEs (CVE‑2026‑1281, CVE‑2026‑1340) in Ivanti Endpoint Manager Mobile are being actively exploited in the wild, allowing unauthenticated attackers to remotely execute arbitrary code and take full control of the MDM infrastructure.

    019068325.5K
    39.8K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🍯It's Saturday, but CVE-2026-1281 / CVE-2026-1340 (Ivanti EPMM) exploitation is in full swing. Some observed exploit IPs: 104.28.249.214 Cloudflare 🇰🇷 45.32.114.222 The Constant Company 🇸🇬 74.113.96.18 DDPS Networks 🇯🇵 45.127.35.186 Dromatics Systems 🇸🇬 122.10.117.244 Overcasts Limited 🇭🇰 103.20.235.155 Shock Hosting 🇸🇬 The vulnerability payload allows attackers to embed their own bash scripts, so payloads contain good intel about post-exploit intent & second-level infrastructure. View live threat intelligence against Ivanti EPMM attacks (Defused TF account required) 👉 https://console.defusedcyber.com/intel

    Post summary

    Multiple IPs are actively exploiting CVE-2026-1281/1340 on Ivanti EPMM, with attackers embedding custom bash scripts as payloads.

    1143682313.4K
    6.0K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Ivanti Endpoint Manager Mobile (EPMM) code injection vulnerability CVE-2026-1281 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/KrNsuKD5gO

    Post summary

    The tweet announces that CVE‑2026‑1281, an Ivanti Endpoint Manager Mobile code injection flaw, has been observed in the wild and directs users to a DHS page for mitigation steps.

    223062613.7K
    291.8K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨 Exploitation of the recent Ivanti EPMM vulns CVE-2026-1281 / CVE-2026-1340 continues extremely heavily, with 863 individually observed exploit events since the launch of the vulnerability (!) Payloads are highly varied, including enumeration as well as reverse and web shells This attacker drops an obfuscated payload which checks if a webshell doesn't exist yet and if it doesn't, they upload one Track Ivanti exploitation activity in real-time 👉 https://console.defusedcyber.com/capabilities

    Post summary

    The post reports ongoing active exploitation of the Ivanti EPMM CVE-2026-1281/1340 with hundreds of observed attacks, but does not provide a PoC, exploit code, patch, or detailed vulnerability technical information.

    0131611110.9K
    6.0K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨 Ivanti has released fixes for 2 critical EPMM vulns (CVE-2026-1281, CVE-2026-1340) enabling unauthenticated remote command execution. Active exploitation already observed. Track exploit activity live via our Ivanti EPMM honeypot intel feed 👉 https://console.defusedcyber.com/intel https://t.co/LE9rrs4LaM

    Post summary

    Ivanti released fixes for CVE‑2026‑1281 and CVE‑2026‑1340, which allow unauthenticated remote command execution. Active exploitation has been observed, with live tracking available via an Ivanti EPMM honeypot intel feed.

    212240128.2K
    6.0K followersView on X
  • Florian Roth ⚡️@cyb3rops
    General

    When your CMS isn't built for cyber ... https://hub.ivanti.com/s/article/Analysis-Guidance-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US - it swallowed the * - it escaped the ( and ) and | from my POV the regex should be ^.*\/mifs\/c\/(aft|app)store.*theValue[^,] and for performance reasons \/mifs\/c\/(aft|app)store.{10,80}theValue[^,] https://t.co/yCzPIJGV2n

    Post summary

    The excerpt links to Ivanti’s analysis of CVE-2026-1281 and CVE-2026-1340 but does not provide PoC, exploit code, patch details, or in-depth technical data.

    05044165.7K
    215.8K followersView on X
  • watchTowr@watchtowrcyber
    Active Exploitation

    When Ivanti disclosed EPMM RCEs (CVE-2026-1281, CVE-2026-1340) w/ active exploitation, watchTowr was already moving. Instinct alerted. Rapid Reaction validated exposure. Attacker Eye captured backdoors. Active Defense auto-mitigated. Know your exposure before the world does. https://t.co/KZIIoE41Ov

    Post summary

    The tweet reports that when Ivanti disclosed the two EPMM RCE CVEs, active exploitation was already underway, and the author’s security solutions detected and auto‑mitigated the threats.

    18043105.1K
    10.9K followersView on X
  • Costin Raiu@craiu
    Active Exploitation

    New Ivanti CVSS 9.8 0day used in the wild, just patched: CVE-2026-1281 & CVE-2026-1340. If you run Ivanti stuff, patch ASAP. No IoCs, no details. Patch: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US

    Post summary

    The post announces that the Ivanti CVEs 2026‑1281 and 2026‑1340 are being actively exploited and have just been patched, with no PoC or exploit code disclosed.

    11703475.5K
    39.4K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Active Exploitation

    We have started to report webshells (or other exploitation artifacts) found on Ivanti EPMM devices, likely compromised via CVE-2026-1281. 56 IPs found on 2026-02-06 Data in https://www.shadowserver.org/what-we-do/network-reporting/compromised-website-report/ Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=compromised_website&source=compromised_website6&tag=ivanti-epmm-compromised%2B&data_set=count&scale=log&auto_update=on Thank you to @NCA_KSA for the heads up! https://t.co/jsbbqNSkz5

    Post summary

    The post documents webshells discovered on Ivanti EPMM devices, indicating active exploitation of CVE-2026-1281, with 56 compromised IPs identified on 2026-02-06.

    216222109.1K
    21.6K followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-1281 (CVSS 9.8): Ivanti Endpoint Manager Mobile Mobile Command Execution A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Search by vul.cve Filter 👉 vul.cve="CVE-2026-1281" ZoomEye Dork 👉 app="Ivanti Endpoint Manager Mobile" 6k+ exposed instances. ZoomEye Link: https://www.zoomeye.ai/searchResult?q=dnVsLmN2ZT0iQ1ZFLTIwMjYtMTI4MSI=&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260130 Refer: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340 #ZoomEye #NetSec #OSINT #CyberSecurity #IvantiVuln #EndpointSecurity #MobileThreat #ZeroDay

    Post summary

    The tweet announces CVE‑2026‑1281 in Ivanti Endpoint Manager Mobile, highlighting a code injection that permits unauthenticated remote code execution and reports over 6,000 exposed instances found via ZoomEye.

    01103263.7K
    11.9K followersView on X
  • ian@adversarialy
    Active Exploitation

    Caught even earlier using AdaptixC2 and this PoC for the EPMM vuln: https://github.com/MehdiLeDeaut/CVE-2026-1281-Ivanti-EPMM-RCE The ability to pivot between @Huntio & @DefusedCyber can result in some pretty interesting findings #opendir https://t.co/mvwXrCIZDr

    Post summary

    The tweet documents interception of AdaptixC2 usage and a PoC for CVE‑2026‑1281, confirming the vulnerability is actively exploited, though no patch or mitigation details are provided.

    37126109.9K
    35 followersView on X
  • GreyNoise@GreyNoiseIO
    Active Exploitation

    83% of observed Ivanti EPMM exploitation (CVE-2026-1281) traces to one bulletproof IP that isn't on any published IOC list. The IPs that are? VPN exits with zero Ivanti activity. We broke down who's actually doing this ⬇️ https://www.greynoise.io/blog/active-ivanti-exploitation #Ivanti #ThreatIntel #CVE20261281 #InfoSec

    Post summary

    The tweet reports that a majority of observed exploitation attempts for CVE‑2026‑1281 originate from a single bullet‑proof IP, indicating ongoing real‑world attacks.

    2703174.0K
    29.3K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Active Exploitation

    Spike in Ivanti EPMM CVE-2026-1281 RCE exploitation attempts seen by our sensors last 24 hours from at least 13 source IPs. In our scans, we see ~1600 exposed instances worldwide (no vulnerability assessment). Top exposed: Germany Ivanti hotfix guidance: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US https://t.co/LpaQWHPxyD

    Post summary

    The post reports a significant spike in active exploitation attempts of CVE‑2026‑1281 with many exposed instances and points to vendor hot‑fix guidance.

    11212653.9K
    21.6K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-1281: Safe indicator check for Ivanti EPMM & CVE-2026-1340 related paths GitHub: https://github.com/Ashwesker/Ashwesker-CVE-2026-1281 https://t.co/D2Q9lkWsqT

    Post summary

    The tweet directs readers to a GitHub repository that appears to host a proof‑of‑concept or indicator check for CVE‑2026‑1281, without providing exploitation code, patch information, or evidence of active exploitation.

    0602694.9K
    165.0K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager_mobile---
Appivantiendpoint_manager_mobile12.5.1.0--
Appivantiendpoint_manager_mobile12.6.0.0--
Appivantiendpoint_manager_mobile12.6.1.0--
Appivantiendpoint_manager_mobile12.7.0.0--

Explore more