Ivanti issued emergency patches for two critical zero-day vulnerabilities in Endpoint Manager Mobile (EPMM)—CVE-2026-1281 and CVE-2026-1340—described as code-injection flaws that can enable pre-auth remote code execution. Reporting indicates successful exploitation could allow attackers to run arbitrary code and potentially access sensitive device and user data managed by EPMM, elevating risk for organizations using the product for mobile device management.
Technical discussion and community commentary amplified the disclosure, pointing to detailed research write-ups (including analysis focused on exploitation mechanics) and reinforcing the urgency of patching internet-exposed EPMM instances. Separate industry coverage during the same period also emphasized broader 2026 security priorities (AI-enabled social engineering, quantum-readiness, and general vulnerability management), but did not add incident-specific details about the Ivanti EPMM zero-days beyond the general call to improve patching discipline.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Late-January reporting said EU data breach notifications had risen 22%, averaging more than 400 per day, while GDPR fines in 2025 totaled about €1.2 billion. The increase came amid policy reform discussions tied to Digital Omnibus, NIS2, and DORA.
Employees at several U.S. companies were targeted in phishing and vishing attacks, with ShinyHunters claiming responsibility and issuing extortion demands. The activity highlighted continued reliance on social engineering for initial access and pressure tactics.
Cyble reported on ShadowHS, a stealthy fileless in-memory Linux post-exploitation framework that uses AES-encrypted payloads and memory execution to evade detection. The tooling was described as supporting credential theft, lateral movement, privilege escalation, cryptomining, and data exfiltration.
Delta, a Russian alarm and vehicle security provider, suffered a major cyberattack that disrupted services for tens of thousands of customers. The company said there was no confirmed customer data breach, though an unverified leaked dataset was reportedly circulating online.
CISA added CVE-2026-1281 to its Known Exploited Vulnerabilities catalog and gave U.S. federal civilian agencies a two-day deadline to remediate. This indicated active exploitation serious enough to trigger urgent government action.
Ivanti issued emergency fixes for two critical pre-authentication code injection vulnerabilities in Endpoint Manager Mobile, tracked as CVE-2026-1281 and CVE-2026-1340. The flaws were described as zero-days affecting EPMM deployments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcethecyberexpress.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.