International Cyber Digest[verified]@IntCyberDigestActive Exploitation
Dutch agencies and government bodies were breached through two critical 0‑day vulnerabilities in Ivanti EPMM, CVE‑2026‑1281 and CVE‑2026‑1340, indicating active exploitation.
watchTowr[verified]@watchtowrcyberDisclosure
The post presents a research analysis of two newly disclosed pre‑auth RCE vulnerabilities in Ivanti EPMM (CVE‑2026‑1281 & CVE‑2026‑1340), offering technical insights for clients but not providing PoC, exploits, or patches.
watchTowr[verified]@watchtowrcyberDisclosure
watchTowr has alerted clients to new unauthenticated RCE CVEs (2026‑1281/1340) affecting Ivanti EPMM and offers support via its website, but does not disclose PoC, exploits, patches, or evidence of active exploitation.
blackorbird[verified]@blackorbirdActive Exploitation
Two critical zero‑day CVEs (CVE-2026-1281 and CVE-2026-1340) in Ivanti Endpoint Manager Mobile are actively exploited in the wild, allowing unauthenticated remote code execution without user interaction. The text lacks PoC, exploit code, or patch information.
Florian Roth ⚡️[verified]@cyb3ropsGeneral
The tweet links to Ivanti guidance on two CVEs and includes regex snippets, but provides no further technical or exploit details.
watchTowr[verified]@watchtowrcyberActive Exploitation
The tweet confirms that CVE-2026-1281 and CVE-2026-1340 were being actively exploited at the time of Ivanti’s disclosure, with attackers already deploying backdoors and defenses responding. No PoC, exploit code, or patch information is provided.
Costin Raiu[verified]@craiuPatch
An Ivanti 0day (CVE‑2026‑1281 & CVE‑2026‑1340) is actively exploited and has been patched; the post urges immediate patching with no IoCs disclosed.
ZoomEye[verified]@zoomeye_teamDisclosure
The post announces a high‑severity vulnerability in Ivanti Endpoint Manager Mobile, providing technical details and linking to a vendor advisory that likely contains patch information.