Quick Summary
The Securityish Brief
Recent analysis by GreyNoise revealed that 83% of exploitation attempts against Ivanti Endpoint Manager Mobile (EPMM) can be traced to a single IP address, 193.24.123.42, on bulletproof hosting infrastructure operated by PROSPERO. Between February 1 and 9, 2026, a total of 417 exploitation sessions were recorded from eight unique source IP addresses, with the majority linked to this single IP. The vulnerabilities being targeted are CVE-2026-1281 and CVE-2026-1340, both of which have a CVSS score of 9.8, indicating critical severity and the potential for unauthenticated remote code execution.
Ivanti acknowledged that a very limited number of customers were impacted by these zero-day exploits. Notably, multiple European agencies, including the Dutch Data Protection Authority and the European Commission, reported being targeted by threat actors leveraging these vulnerabilities. The malicious activity is characterized by a high degree of automation, with the same host exploiting three other unrelated CVEs and utilizing over 300 unique user agent strings.
GreyNoise also noted that 85% of the exploitation sessions confirmed the target’s vulnerability via DNS without deploying malware or exfiltrating data. This pattern suggests a reconnaissance phase where attackers catalog potential targets before executing further exploits.
Implications for Organizations
The exploitation of EPMM poses significant risks, as it provides access to device management infrastructure for entire organizations. This access can facilitate lateral movement within networks, bypassing traditional security measures. Organizations with internet-facing Mobile Device Management (MDM) systems should be particularly vigilant, as critical vulnerabilities can be exploited within hours of disclosure.
Given the automated nature of the attacks and the use of diverse fingerprints, organizations must audit their MDM infrastructure and review DNS logs for any suspicious activity. The ongoing threat from PROSPERO’s infrastructure highlights the importance of proactive security measures.
To mitigate risks, Ivanti EPMM users are advised to apply available patches and monitor for specific indicators of compromise, such as the /mifs/403.jsp path. Blocking PROSPERO’s autonomous system (AS200593) at the network perimeter level is also recommended to prevent further exploitation.
- Ivanti Endpoint Manager Mobile (EPMM): Affected by critical vulnerabilities allowing remote code execution.
- CVE-2026-1281: A critical vulnerability in EPMM with a CVSS score of 9.8.
- CVE-2026-1340: Another critical vulnerability in EPMM that can be exploited similarly.
- PROSPERO: The bulletproof hosting provider linked to the exploitation attempts.
- GreyNoise: The threat intelligence firm that reported on the exploitation sessions.
Key Takeaways
- Apply patches for Ivanti EPMM to address critical vulnerabilities.
- Audit your internet-facing Mobile Device Management (MDM) infrastructure for security risks.
- Review DNS logs for any suspicious activity related to OAST-pattern callbacks.
- Monitor for the /mifs/403.jsp path on EPMM instances to detect potential compromises.
- Block PROSPERO’s autonomous system (AS200593) at your network perimeter to prevent exploitation.
Key Terms & Concepts
- CVE-2026-1281: In this article, CVE-2026-1281 refers to a critical vulnerability in Ivanti EPMM that allows unauthenticated remote code execution.
- CVE-2026-1340: CVE-2026-1340 is another critical vulnerability in Ivanti EPMM that can also be exploited for remote code execution.
- PROSPERO: PROSPERO is a bulletproof hosting provider linked to the exploitation of Ivanti EPMM vulnerabilities.
- GreyNoise: GreyNoise is a threat intelligence firm that reported on the exploitation sessions targeting Ivanti EPMM.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.