Ivanti warned that its on-premises Endpoint Manager Mobile (EPMM) product contains two critical vulnerabilities, CVE-2026-1281 and CVE-2026-1340, that can let an unauthenticated remote attacker execute arbitrary commands or code over the network. The flaws affect exposed EPMM servers and create a path to full server compromise and possible lateral movement into internal environments. Ivanti said its cloud offerings, including Ivanti Neurons for MDM, and the separate Ivanti Endpoint Manager (EPM) product are not affected, and it released patches, incident-response guidance, and a detection tool to help customers assess exposure and compromise.
Follow-up advisories said the vulnerabilities are being actively exploited, prompting defenders to inspect EPMM systems for anomalous logs, unauthorized administrator-account changes, and suspicious device-configuration modifications. A later update citing Germany's BSI said exploitation may date back to summer 2025, expanding the scope of required forensic review beyond recent activity. Public reporting from security researchers, including Palo Alto Networks Unit 42 and vulnerability tracking sources, reinforced that the issue is an unauthenticated remote code execution risk requiring immediate patching and retrospective compromise hunting on affected on-premises deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published reporting that the critical Ivanti EPMM vulnerabilities were under active exploitation. This reinforced public awareness of the in-the-wild abuse of the flaws.
A February update cited a German BSI report saying exploitation had already taken place as early as summer 2025. Based on that finding, defenders were urged to review historical evidence of compromise rather than only recent activity.
Ivanti published incident investigation guidance and a detection tool to help customers assess whether EPMM servers had been compromised. The tool was later updated to improve compromise assessment support.
An update to the security notice stated that attackers were actively exploiting CVE-2026-1281 and CVE-2026-1340 in the wild. Defenders were advised to inspect EPMM devices for signs of compromise, including anomalous logs and unauthorized changes to admin accounts or device configuration.
On January 30, 2026, watchTowr Labs released a technical report with proof-of-concept exploit code for CVE-2026-1281 and CVE-2026-1340. The publication increased urgency for defenders to patch Ivanti EPMM systems and review logs for signs of compromise.
Finland's Traficom issued a security notice warning that the Ivanti EPMM vulnerabilities were critical and required immediate patching. The notice clarified that Ivanti cloud products such as Ivanti Neurons for MDM and the separate Ivanti Endpoint Manager product were not affected.
Ivanti disclosed critical vulnerabilities affecting on-premises Endpoint Manager Mobile, including CVE-2026-1281 and CVE-2026-1340, and published guidance to patch affected systems. The flaws could allow unauthenticated remote command or code execution against the EPMM server.
A later-cited German BSI report said exploitation of the Ivanti Endpoint Manager Mobile flaws had already occurred by summer 2025. This indicates the vulnerabilities were being abused well before public disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourcebsi.bund.de
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcekyberturvallisuuskeskus.fi
Open sourcethehackerwire.com
Open sourcerapid7.com
Open sourcecloud.projectdiscovery.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.