CVE-2026-1340Active Exploitation(ivanti / endpoint_manager_mobile)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 56 mentions and remains active

Immediate actions

  • Patch ivanti endpoint_manager_mobile systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-11. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager_mobile

Threat summary

  • Active exploitation appears in 166 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 243 mentions across 51 observed days

What's happening

  • Active exploitation reported across 166 signals
  • Exploit tool or code specified in 11 signals
  • PoC mentioned or linked in 19 signals
  • Patch or workaround mentioned in 92 signals
  • Technical details provided in 154 signals
  • Disclosure: 43 classified signals
  • Peaked 49d ago at 56 mentions (2026-01-30); latest day: 1
  • 243 total mentions across 51 days

Affected systems

Vendors
Products
endpoint_manager_mobile

Deep dive

Activity timeline243 mentions / 51d
014284256Mentions · 2026-01-29: 13Mentions · 2026-01-30: 56Mentions · 2026-01-31: 10Mentions · 2026-02-01: 5Mentions · 2026-02-02: 17Mentions · 2026-02-03: 7Mentions · 2026-02-04: 4Mentions · 2026-02-05: 3Mentions · 2026-02-06: 1Mentions · 2026-02-07: 2Mentions · 2026-02-09: 6Mentions · 2026-02-10: 9Mentions · 2026-02-11: 3Mentions · 2026-02-12: 10Mentions · 2026-02-13: 2Mentions · 2026-02-14: 1Mentions · 2026-02-16: 2Mentions · 2026-02-17: 4Mentions · 2026-02-18: 12Mentions · 2026-02-19: 5Mentions · 2026-02-20: 2Mentions · 2026-02-23: 2Mentions · 2026-02-24: 2Mentions · 2026-02-25: 3Mentions · 2026-02-26: 2Mentions · 2026-02-27: 2Mentions · 2026-03-03: 1Mentions · 2026-03-06: 3Mentions · 2026-03-08: 1Mentions · 2026-03-10: 1Mentions · 2026-03-20: 1Mentions · 2026-03-26: 3Mentions · 2026-03-27: 1Mentions · 2026-03-29: 2Mentions · 2026-04-02: 1Mentions · 2026-04-06: 1Mentions · 2026-04-08: 11Mentions · 2026-04-09: 10Mentions · 2026-04-10: 2Mentions · 2026-04-11: 4Mentions · 2026-04-12: 1Mentions · 2026-04-15: 2Mentions · 2026-04-16: 1Mentions · 2026-04-20: 2Mentions · 2026-05-04: 3Mentions · 2026-05-07: 1Mentions · 2026-05-08: 2Mentions · 2026-05-11: 1Mentions · 2026-06-25: 1Mentions · 2026-08-11: 1Mentions · 2026-09-18: 1PoC Mentioned / Linked · 2026-01-30: 2PoC Mentioned / Linked · 2026-02-01: 1PoC Mentioned / Linked · 2026-02-04: 1PoC Mentioned / Linked · 2026-02-09: 2PoC Mentioned / Linked · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-12: 2PoC Mentioned / Linked · 2026-02-16: 2PoC Mentioned / Linked · 2026-02-19: 2PoC Mentioned / Linked · 2026-03-08: 1PoC Mentioned / Linked · 2026-03-26: 3PoC Mentioned / Linked · 2026-04-09: 1PoC Mentioned / Linked · 2026-05-07: 1Exploit Tool / Code · 2026-01-30: 1Exploit Tool / Code · 2026-02-09: 1Exploit Tool / Code · 2026-02-11: 1Exploit Tool / Code · 2026-02-12: 1Exploit Tool / Code · 2026-02-16: 1Exploit Tool / Code · 2026-02-25: 1Exploit Tool / Code · 2026-03-08: 1Exploit Tool / Code · 2026-03-26: 1Exploit Tool / Code · 2026-04-02: 1Exploit Tool / Code · 2026-04-09: 1Exploit Tool / Code · 2026-05-07: 1Active Exploitation · 2026-01-29: 6Active Exploitation · 2026-01-30: 33Active Exploitation · 2026-01-31: 8Active Exploitation · 2026-02-01: 1Active Exploitation · 2026-02-02: 11Active Exploitation · 2026-02-03: 4Active Exploitation · 2026-02-04: 4Active Exploitation · 2026-02-05: 3Active Exploitation · 2026-02-09: 5Active Exploitation · 2026-02-10: 7Active Exploitation · 2026-02-11: 3Active Exploitation · 2026-02-12: 8Active Exploitation · 2026-02-13: 2Active Exploitation · 2026-02-14: 1Active Exploitation · 2026-02-16: 2Active Exploitation · 2026-02-17: 4Active Exploitation · 2026-02-18: 11Active Exploitation · 2026-02-19: 3Active Exploitation · 2026-02-20: 1Active Exploitation · 2026-02-23: 1Active Exploitation · 2026-02-24: 2Active Exploitation · 2026-02-25: 2Active Exploitation · 2026-02-26: 2Active Exploitation · 2026-02-27: 2Active Exploitation · 2026-03-06: 2Active Exploitation · 2026-03-08: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-26: 2Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-03-29: 1Active Exploitation · 2026-04-02: 1Active Exploitation · 2026-04-06: 1Active Exploitation · 2026-04-08: 8Active Exploitation · 2026-04-09: 9Active Exploitation · 2026-04-10: 2Active Exploitation · 2026-04-11: 3Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-05-04: 3Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-05-08: 1Patch / Workaround · 2026-01-29: 6Patch / Workaround · 2026-01-30: 26Patch / Workaround · 2026-01-31: 7Patch / Workaround · 2026-02-01: 1Patch / Workaround · 2026-02-02: 5Patch / Workaround · 2026-02-03: 3Patch / Workaround · 2026-02-05: 2Patch / Workaround · 2026-02-09: 2Patch / Workaround · 2026-02-10: 2Patch / Workaround · 2026-02-11: 2Patch / Workaround · 2026-02-12: 5Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-02-16: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-02-18: 2Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-04-08: 6Patch / Workaround · 2026-04-09: 4Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-11: 2Patch / Workaround · 2026-04-12: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-08: 2Technical Details · 2026-01-29: 10Technical Details · 2026-01-30: 35Technical Details · 2026-01-31: 6Technical Details · 2026-02-01: 2Technical Details · 2026-02-02: 9Technical Details · 2026-02-03: 4Technical Details · 2026-02-04: 1Technical Details · 2026-02-05: 2Technical Details · 2026-02-09: 6Technical Details · 2026-02-10: 5Technical Details · 2026-02-11: 2Technical Details · 2026-02-12: 6Technical Details · 2026-02-13: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-17: 2Technical Details · 2026-02-18: 5Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 2Technical Details · 2026-02-23: 1Technical Details · 2026-02-24: 2Technical Details · 2026-02-25: 3Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-08: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-26: 2Technical Details · 2026-04-02: 1Technical Details · 2026-04-08: 10Technical Details · 2026-04-09: 8Technical Details · 2026-04-10: 1Technical Details · 2026-04-11: 4Technical Details · 2026-04-15: 2Technical Details · 2026-04-16: 1Technical Details · 2026-04-20: 2Technical Details · 2026-05-04: 2Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 2Technical Details · 2026-06-25: 1Technical Details · 2026-08-11: 1Technical Details · 2026-09-18: 101-2902-0302-0902-1402-2002-2703-2004-0604-1205-0709-18
Signal classification6 categories
Active Exploitation
14158.0%
Disclosure
4317.7%
Patch
3916.0%
General
156.2%
PoC
41.6%
Exploit
10.4%
Referenced assets200 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-2913
Active Exploitation6Disclosure4Patch3
2026-01-3056
Active Exploitation19Disclosure16Exploit1General5Patch15
2026-01-3110
Active Exploitation6Patch4
2026-02-015
Active Exploitation1Disclosure3PoC1
2026-02-0217
Active Exploitation9Disclosure4General1Patch3
2026-02-037
Active Exploitation4Disclosure2Patch1
2026-02-044
Active Exploitation4
2026-02-053
Active Exploitation2Patch1
2026-02-061
General1
2026-02-072
General2
2026-02-096
Active Exploitation5Disclosure1
2026-02-109
Active Exploitation7Disclosure1General1
2026-02-113
Active Exploitation3
2026-02-1210
Active Exploitation8General1PoC1
2026-02-132
Active Exploitation2
2026-02-141
Active Exploitation1
2026-02-162
Active Exploitation2
2026-02-174
Active Exploitation4
2026-02-1812
Active Exploitation11General1
2026-02-195
Active Exploitation2Disclosure2PoC1
2026-02-202
Active Exploitation1Disclosure1
2026-02-232
Active Exploitation1General1
2026-02-242
Active Exploitation2
2026-02-253
Active Exploitation2Disclosure1
2026-02-262
Active Exploitation2
2026-02-272
Active Exploitation2
2026-03-031
Disclosure1
2026-03-063
Active Exploitation2Patch1
2026-03-081
Active Exploitation1
2026-03-101
Active Exploitation1
2026-03-201
Active Exploitation1
2026-03-263
Active Exploitation2PoC1
2026-03-271
Active Exploitation1
2026-03-292
Active Exploitation1Patch1
2026-04-021
Active Exploitation1
2026-04-061
Active Exploitation1
2026-04-0811
Active Exploitation5Disclosure3Patch3
2026-04-0910
Active Exploitation7General1Patch2
2026-04-102
Active Exploitation2
2026-04-114
Active Exploitation3Patch1
2026-04-121
Patch1
2026-04-152
Patch2
2026-04-161
Active Exploitation1
2026-04-202
Active Exploitation1Disclosure1
2026-05-043
Active Exploitation3
2026-05-071
Active Exploitation1
2026-05-082
Active Exploitation1Patch1
2026-05-111
Disclosure1
2026-06-251
Disclosure1
2026-08-111
General1
2026-09-181
Disclosure1
Full discourse20 posts
  • International Cyber Digest@IntCyberDigest
    Active Exploitation

    ❗️ Leaked: Dutch Prison Agency (DJI) hacked This breach, and those of the Dutch Data Protection Authority, the Council for the Judiciary, the European Commission and Finland’s government, all trace back to two critical 0-day vulnerabilities in Ivanti EPMM: CVE-2026-1281 and CVE-2026-1340.

    Post summary

    Dutch agencies and government bodies were breached through two critical 0‑day vulnerabilities in Ivanti EPMM, CVE‑2026‑1281 and CVE‑2026‑1340, indicating active exploitation.

    135362947024.1K
    92.7K followersView on X
  • watchTowr@watchtowrcyber
    Disclosure

    Someone knows Bash disgustingly well, and we love it. Here's our analysis of the Ivanti EPMM Pre-Auth RCE vulnerabilities - CVE-2026-1281 & CVE-2026-1340. This research fuels our technology, enabling our clients to accurately determine their exposure. https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340

    Post summary

    The post presents a research analysis of two newly disclosed pre‑auth RCE vulnerabilities in Ivanti EPMM (CVE‑2026‑1281 & CVE‑2026‑1340), offering technical insights for clients but not providing PoC, exploits, or patches.

    870622712031.2K
    11.0K followersView on X
  • Defused@DefusedCyber
    General

    🚨 We are seeing pre-exploitation recon for Ivanti CVE-2026-1281/CVE-2026-1340 since the early AM hours today Attackers can probe the /mifs/c/appstore path to determine if the target is vulnerable to CVE-2026-1281 / CVE-2026-1340 No public POC exists as of right now. https://t.co/AVW15ZnYda

    Post summary

    Report notes attackers are conducting reconnaissance for Ivanti CVE-2026-1281/CVE-2026-1340, probing the /mifs/c/appstore path to identify vulnerable systems, but no public PoC or patch is available.

    4161982611.5K
    6.0K followersView on X
  • watchTowr@watchtowrcyber
    Disclosure

    🚨 The watchTowr team is rapidly reacting to CVE-2026-1281 & CVE-2026-1340 - unauth RCE vulnerabilities within Ivanti's Endpoint Manager Mobile (EPMM). Active watchTowr Platform clients have been made aware of their exposure - reach out via the watchTowr website for support. https://t.co/wkYOHloPPJ

    Post summary

    watchTowr has alerted clients to new unauthenticated RCE CVEs (2026‑1281/1340) affecting Ivanti EPMM and offers support via its website, but does not disclose PoC, exploits, patches, or evidence of active exploitation.

    3231802211.2K
    11.0K followersView on X
  • Unit 42@Unit42_Intel
    Active Exploitation

    We detail exploitation of zero-day vulnerabilities CVE-2026-1281 and CVE-2026-1340 discovered in Ivanti EPMM. A global exploitation campaign is affecting multiple critical sectors: https://bit.ly/4aAho7Q https://t.co/BBts3tDQRl

    Post summary

    The post announces that zero‑day vulnerabilities CVE-2026-1281 and CVE-2026-1340 in Ivanti EPMM are being actively exploited worldwide, without providing a PoC, exploit code, patch, or technical details.

    1322691917.7K
    66.5K followersView on X
  • blackorbird@blackorbird
    Active Exploitation

    Two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) affecting Ivanti Endpoint Manager Mobile (EPMM) are being actively exploited in the wild, affecting enterprise mobile fleets and corporate networks. These vulnerabilities allow unauthenticated attackers to remotely execute arbitrary code on target servers, granting them full control over mobile device management (MDM) infrastructure without requiring user interaction or credentials. https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/

    Post summary

    Two critical zero‑day CVEs (CVE-2026-1281 and CVE-2026-1340) in Ivanti Endpoint Manager Mobile are actively exploited in the wild, allowing unauthenticated remote code execution without user interaction. The text lacks PoC, exploit code, or patch information.

    019068325.5K
    39.8K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🍯It's Saturday, but CVE-2026-1281 / CVE-2026-1340 (Ivanti EPMM) exploitation is in full swing. Some observed exploit IPs: 104.28.249.214 Cloudflare 🇰🇷 45.32.114.222 The Constant Company 🇸🇬 74.113.96.18 DDPS Networks 🇯🇵 45.127.35.186 Dromatics Systems 🇸🇬 122.10.117.244 Overcasts Limited 🇭🇰 103.20.235.155 Shock Hosting 🇸🇬 The vulnerability payload allows attackers to embed their own bash scripts, so payloads contain good intel about post-exploit intent & second-level infrastructure. View live threat intelligence against Ivanti EPMM attacks (Defused TF account required) 👉 https://console.defusedcyber.com/intel

    Post summary

    The post reports that CVE-2026-1281 and CVE-2026-1340 are actively being exploited, citing observed attacker IPs and the ability to embed custom bash scripts in the payload.

    1143682313.4K
    6.0K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨 Exploitation of the recent Ivanti EPMM vulns CVE-2026-1281 / CVE-2026-1340 continues extremely heavily, with 863 individually observed exploit events since the launch of the vulnerability (!) Payloads are highly varied, including enumeration as well as reverse and web shells This attacker drops an obfuscated payload which checks if a webshell doesn't exist yet and if it doesn't, they upload one Track Ivanti exploitation activity in real-time 👉 https://console.defusedcyber.com/capabilities

    Post summary

    Heavy, ongoing exploitation of Ivanti EPMM CVE‑2026‑1281 and CVE‑2026‑1340 is reported, with 863 observed attack events and varied payloads including enumeration, reverse, and web shells.

    0131611110.9K
    6.0K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Ivanti Endpoint Manager Mobile code injection vulnerability CVE-2026-1340 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/2XsPCUy78c

    Post summary

    The tweet confirms CVE‑2026‑1340 is actively exploited and has been cataloged as a known vulnerability, but it does not provide PoC, exploit code, or remediation details.

    32304779.4K
    298.7K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨 Ivanti has released fixes for 2 critical EPMM vulns (CVE-2026-1281, CVE-2026-1340) enabling unauthenticated remote command execution. Active exploitation already observed. Track exploit activity live via our Ivanti EPMM honeypot intel feed 👉 https://console.defusedcyber.com/intel https://t.co/LE9rrs4LaM

    Post summary

    Ivanti has issued patches for two critical remote command execution bugs (CVE‑2026‑1281, CVE‑2026‑1340) while active exploitation in the wild has been observed and is being tracked through a honeypot intel feed.

    212240128.2K
    6.0K followersView on X
  • Florian Roth ⚡️@cyb3rops
    General

    When your CMS isn't built for cyber ... https://hub.ivanti.com/s/article/Analysis-Guidance-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US - it swallowed the * - it escaped the ( and ) and | from my POV the regex should be ^.*\/mifs\/c\/(aft|app)store.*theValue[^,] and for performance reasons \/mifs\/c\/(aft|app)store.{10,80}theValue[^,] https://t.co/yCzPIJGV2n

    Post summary

    The tweet links to Ivanti guidance on two CVEs and includes regex snippets, but provides no further technical or exploit details.

    05044165.7K
    215.8K followersView on X
  • watchTowr@watchtowrcyber
    Active Exploitation

    When Ivanti disclosed EPMM RCEs (CVE-2026-1281, CVE-2026-1340) w/ active exploitation, watchTowr was already moving. Instinct alerted. Rapid Reaction validated exposure. Attacker Eye captured backdoors. Active Defense auto-mitigated. Know your exposure before the world does. https://t.co/KZIIoE41Ov

    Post summary

    The tweet confirms that CVE-2026-1281 and CVE-2026-1340 were being actively exploited at the time of Ivanti’s disclosure, with attackers already deploying backdoors and defenses responding. No PoC, exploit code, or patch information is provided.

    18043105.1K
    10.9K followersView on X
  • Costin Raiu@craiu
    Patch

    New Ivanti CVSS 9.8 0day used in the wild, just patched: CVE-2026-1281 & CVE-2026-1340. If you run Ivanti stuff, patch ASAP. No IoCs, no details. Patch: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US

    Post summary

    An Ivanti 0day (CVE‑2026‑1281 & CVE‑2026‑1340) is actively exploited and has been patched; the post urges immediate patching with no IoCs disclosed.

    11703475.5K
    39.4K followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-1281 (CVSS 9.8): Ivanti Endpoint Manager Mobile Mobile Command Execution A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Search by vul.cve Filter 👉 vul.cve="CVE-2026-1281" ZoomEye Dork 👉 app="Ivanti Endpoint Manager Mobile" 6k+ exposed instances. ZoomEye Link: https://www.zoomeye.ai/searchResult?q=dnVsLmN2ZT0iQ1ZFLTIwMjYtMTI4MSI=&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260130 Refer: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340 #ZoomEye #NetSec #OSINT #CyberSecurity #IvantiVuln #EndpointSecurity #MobileThreat #ZeroDay

    Post summary

    The post announces a high‑severity vulnerability in Ivanti Endpoint Manager Mobile, providing technical details and linking to a vendor advisory that likely contains patch information.

    01103263.7K
    11.9K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Active Exploitation

    Spike in Ivanti EPMM CVE-2026-1281 RCE exploitation attempts seen by our sensors last 24 hours from at least 13 source IPs. In our scans, we see ~1600 exposed instances worldwide (no vulnerability assessment). Top exposed: Germany Ivanti hotfix guidance: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US https://t.co/LpaQWHPxyD

    Post summary

    The post reports a surge of remote code execution attempts against Ivanti EPMM for CVE‑2026‑1281, with 13 source IPs and roughly 1,600 exposed instances worldwide, and directs readers to a vendor hot‑fix link.

    11212653.9K
    21.6K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-1281: Safe indicator check for Ivanti EPMM & CVE-2026-1340 related paths GitHub: https://github.com/Ashwesker/Ashwesker-CVE-2026-1281 https://t.co/D2Q9lkWsqT

    Post summary

    The tweet shares a GitHub repository containing a proof‑of‑concept for CVE‑2026‑1281, but provides no exploit, patch, or active exploitation information.

    0602694.9K
    165.0K followersView on X
  • /r/netsec@_r_netsec
    PoC

    Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340) - watchTowr Labs https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340/

    Post summary

    WatchTowr Labs discloses two new Ivanti EPMM pre‑authentication RCE vulnerabilities (CVE‑2026‑1281 and CVE‑2026‑1340) and includes proof‑of‑concept demonstrations, but does not indicate active exploitation or provide patches.

    0711585.7K
    32.9K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    Based on the recent @watchtowrcyber analysis we upgraded the early Ivanti EPMM CVE-2026-1281 & CVE-2026-1340 recon indicators to exploit attempts View the activity here (Defused TF subscription required) 👇 https://console.defusedcyber.com/s/de05ee3d-eae6-4329-8e34-13e9af806fac/

    Post summary

    The post reports that exploit attempts targeting Ivanti EPMM CVE‑2026‑1281 and CVE‑2026‑1340 were observed, indicating active exploitation in the wild.

    0502332.4K
    6.0K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Active Exploitation

    Unit 42 reports widespread exploitation of Ivanti EPMM zero-days CVE-2026-1281 and CVE-2026-1340, with attackers deploying web shells and backdoors. https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/

    Post summary

    Unit 42 reports that two Ivanti EPMM zero‑days (CVE‑2026‑1281 and CVE‑2026‑1340) are being widely exploited, with attackers deploying web shells and backdoors.

    2501731.1K
    21.3K followersView on X
  • JPCERTコーディネーションセンター@jpcert
    Active Exploitation

    Ivanti Endpoint Manager Mobile(EPMM)の脆弱性(CVE-2026-1281、CVE-2026-1340)に関する注意喚起を公開。すでに脆弱性の悪用が確認されています。開発者が提供する最新の情報をもとに、対策や侵害有無の調査を実施してください。^KK https://www.jpcert.or.jp/at/2026/at260002.html

    Post summary

    An advisory confirms that CVE‑2026‑1281 and CVE‑2026‑1340 in Ivanti Endpoint Manager Mobile are actively exploited; stakeholders are urged to investigate incidents and follow vendor guidance.

    0811445.7K
    33.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager_mobile---

Explore more