Ivanti Discloses Critical EPMM Vulnerabilities Exploited in Zero-Day Attacks
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Ivanti disclosed two critical vulnerabilities in its Endpoint Manager Mobile (EPMM), identified as CVE-2026-1281 and CVE-2026-1340, which were actively exploited in zero-day attacks. Both vulnerabilities are classified as code-injection flaws with a CVSS score of 9.8, allowing attackers to execute arbitrary code on vulnerable devices without authentication. At the time of disclosure, Ivanti noted that a limited number of customers had been affected by these exploits.
The vulnerabilities were triggered through features like In-House Application Distribution and Android File Transfer Configuration. Exploitation attempts can be detected in the Apache access log at /var/log/httpd/https-access_log, with suspicious entries returning 404 HTTP response codes. Ivanti has provided a regular expression to help administrators identify these potentially malicious log entries.
Successful exploitation can grant attackers access to sensitive data stored on the EPMM appliance, including administrator and user names, email addresses, and device identifiers such as IMEI and MAC addresses. If location tracking is enabled, attackers could also access GPS coordinates and nearby cell tower locations.
Ivanti has released RPM scripts to mitigate the vulnerabilities for specific EPMM versions, advising that no downtime is required to apply these patches. However, the company cautions that these hotfixes must be reapplied if the appliance is upgraded before a permanent fix is available, which is expected in EPMM version 12.8.0.0, slated for release in Q1 2026.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-1281 to its Known Exploited Vulnerabilities catalog, mandating federal civilian agencies to apply mitigations by February 1, 2026, or discontinue use of affected systems. This highlights the urgency for organizations using EPMM to take immediate action to secure their systems.
Understanding the Risks
Organizations using Ivanti EPMM should be aware of the potential risks associated with these vulnerabilities. Attackers exploiting these flaws could not only access sensitive information but also make unauthorized configuration changes through the EPMM API or web console. This could lead to further security breaches and data loss.
It is crucial for administrators to monitor access logs for unusual activity and ensure that all security patches are applied promptly. Additionally, organizations should review Sentry logs, as the EPMM can tunnel traffic from mobile devices to internal networks, potentially allowing attackers to move laterally within the network.
Key Takeaways
- Apply the RPM scripts provided by Ivanti for your specific EPMM version to mitigate the vulnerabilities.
- Monitor Apache access logs for entries that return 404 errors, indicating potential exploitation attempts.
- Review Sentry logs for any suspicious activity that may indicate unauthorized access or lateral movement.
- Restore your EPMM from a known-good backup if you suspect it has been compromised.
- Stay informed about the upcoming permanent fix in EPMM version 12.8.0.0 and plan for its implementation.
Key Terms & Concepts
- CVE-2026-1281: In this article, CVE-2026-1281 refers to a critical vulnerability in Ivanti Endpoint Manager Mobile that allows remote code execution.
- CVE-2026-1340: In this article, CVE-2026-1340 refers to another critical vulnerability in Ivanti Endpoint Manager Mobile that enables attackers to execute arbitrary code.
- RPM scripts: In this article, RPM scripts are provided by Ivanti to mitigate the vulnerabilities in specific versions of EPMM.
- zero-day attack: In this article, a zero-day attack refers to an exploit that takes advantage of a previously unknown vulnerability.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.