Ivanti warned that two critical zero-day flaws in Endpoint Manager Mobile (EPMM) — CVE-2026-1281 and CVE-2026-1340 — were being actively exploited, and subsequent reporting described rapid mass exploitation after proof-of-concept code became public. The attacks hit internet-facing EPMM systems used to manage mobile devices, with incident responders documenting a fully automated intrusion chain that successfully exfiltrated sensitive EPMM data and leveraged lesser-known product behaviors alongside an open-source offensive framework. Germany's BSI also issued an alert on active attacks, underscoring the broad operational impact of the campaign.
The exploitation wave affected both opportunistic victims and targeted organizations, including governments. Dutch authorities disclosed that attackers had maintained access to the Dutch Custodial Institutions Agency's EPMM server for about five months, exposing employee names, email addresses, phone numbers, and location data, with officials warning of elevated blackmail and extortion risks. Ivanti's earlier handling of EPMM flaws, including CVE-2023-35082, had already shown that internet-exposed deployments could enable unauthorized access to personally identifiable information, but the company separately clarified that a later May 2026 advisory for Endpoint Manager (EPM) — covering CVE-2026-8109, CVE-2026-8110, and CVE-2026-8111 — involved a different product and was not tied to the EPMM zero-day exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Ivanti published a security advisory for Endpoint Manager (EPM) covering CVE-2026-8109, CVE-2026-8110, and CVE-2026-8111, affecting EPM 2024 SU5 and earlier. The company fixed the issues in Endpoint Manager 2024 SU6 and said it was not aware of customer exploitation before public disclosure, while clarifying these flaws affected EPM rather than EPMM.
Following the confirmed breach, DJI deployed technical and monitoring measures, distributed a response plan to employees, and used National Cyber Security Centre recommendations. Authorities said a full forensic investigation and cause analysis were still underway, with concerns about blackmail and extortion risks to staff.
State Secretary of Justice and Security Van Bruggen confirmed that the Dutch Custodial Institutions Agency (DJI) suffered a breach involving its Ivanti EPMM server. Attackers were found to have maintained access for five months, and exposed data included employee names, email addresses, phone numbers, and location data.
Germany's Federal Office for Information Security (BSI) issued a cyber warning stating that active attacks exploiting Ivanti EPMM zero-day vulnerabilities had been observed. The alert reflected escalating official concern over ongoing exploitation.
In one investigated compromise, an incident response team confirmed attackers used a fully automated and carefully prepared attack chain to exfiltrate sensitive EPMM data. The report also noted lesser-known technical details and a link to an open-source offensive framework.
After the proof-of-concept became public, attackers began broad exploitation of vulnerable Ivanti EPMM systems. Reporting described both opportunistic actors and more targeted operators pursuing specific objectives, including governments and other organizations.
A proof-of-concept exploit for the two critical Ivanti EPMM remote code execution vulnerabilities was published in late January 2026. Subsequent reporting tied this release to a rapid increase in attacker activity.
Ivanti published a security advisory for Ivanti Endpoint Manager Mobile covering CVE-2026-1281 and CVE-2026-1340, warning that the flaws were being exploited as zero-days. This marked the public disclosure of the two critical EPMM issues.
Ivanti said CVE-2023-35082 was patched in EPMM version 11.11.0.0 and recommended network mitigations such as restricting exposed ports because exploitation was possible over HTTP but not HTTPS. The company also noted some customers were exploited after Rapid7 publicly disclosed details and that additional exploitation paths depended on appliance configuration.
Ivanti disclosed the remote unauthenticated API access vulnerability CVE-2023-35082 affecting Ivanti Endpoint Manager Mobile (EPMM) 11.10, 11.9, 11.8 and MobileIron Core 11.7 and below. The flaw could let an internet-facing unauthenticated attacker access users’ personally identifiable information and make limited server changes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
forums.ivanti.com
Open sourcecyberwarzone.com
Open sourcelabs.withsecure.com
Open sourcebsi.bund.de
Open sourcehendryadrian.com
Open sourceforums.ivanti.com
Open sourceforums.ivanti.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.