Ivanti EPMM Zero-Day Vulnerabilities CVE-2026-1281 and CVE-2026-1340 Exploited
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Ivanti has announced security updates to address two critical vulnerabilities in its Ivanti Endpoint Manager Mobile (EPMM) software, specifically CVE-2026-1281 and CVE-2026-1340. Both vulnerabilities have been assigned a CVSS score of 9.8 and allow attackers to execute remote code without authentication. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-1281 to its Known Exploited Vulnerabilities catalog, mandating that federal agencies implement the necessary updates by February 1, 2026.
The vulnerabilities affect several versions of EPMM, including 12.5.0.0 and prior, 12.6.0.0 and prior, and 12.7.0.0 and prior, as well as 12.5.1.0 and 12.6.1.0 and prior. Ivanti has indicated that a very limited number of customers have reported exploitation of their solutions. The vulnerabilities specifically impact the In-House Application Distribution and Android File Transfer Configuration features.
In response to these vulnerabilities, Ivanti has advised users to check their Apache access logs for signs of exploitation attempts. Users should look for 404 HTTP response codes, which indicate potential unauthorized access attempts, as legitimate use would result in 200 HTTP response codes.
In the event of detected compromise, Ivanti recommends restoring the EPMM device from a known good backup or building a replacement device. Users should also reset passwords for local accounts, LDAP service accounts, and any other service accounts configured with the EPMM solution to secure their environment.
Understanding the Risks
The successful exploitation of these vulnerabilities could allow attackers to execute arbitrary code on the EPMM appliance, potentially leading to lateral movement within the connected environment. EPMM contains sensitive information about devices it manages, increasing the risk of data breaches.
Organizations using affected versions of EPMM should prioritize applying the security updates released by Ivanti and monitor their systems for any signs of unauthorized changes or access. Regular audits of administrator accounts and configuration settings can help mitigate risks associated with these vulnerabilities.
Key Takeaways
- Update Ivanti Endpoint Manager Mobile (EPMM) to the latest version to mitigate vulnerabilities.
- Check Apache access logs for 404 HTTP response codes to identify potential exploitation attempts.
- Review administrator accounts for any unauthorized changes or additions.
- Reset passwords for local EPMM accounts and LDAP service accounts to enhance security.
- Restore the EPMM device from a known good backup if signs of compromise are detected.
Key Terms & Concepts
- CVE: In this article, CVE refers to the Common Vulnerabilities and Exposures system that provides a reference-method for publicly known information-security vulnerabilities.
- Remote Code Execution: Remote Code Execution is a type of vulnerability that allows an attacker to execute arbitrary code on a remote system.
- CVSS: CVSS stands for Common Vulnerability Scoring System, which assigns severity scores to vulnerabilities to help organizations prioritize their responses.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.