Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisoryproof-of-concept-releaserapid-weaponization

Ivanti Endpoint Manager Mobile Pre-Auth RCE Zero-Days (CVE-2026-1281, CVE-2026-1340)

Updated 3mo agoFirst seen Jan 30, 20263 sources

Ivanti issued emergency patches for two critical zero-day vulnerabilities in Endpoint Manager Mobile (EPMM)CVE-2026-1281 and CVE-2026-1340—described as code-injection flaws that can enable pre-auth remote code execution. Reporting indicates successful exploitation could allow attackers to run arbitrary code and potentially access sensitive device and user data managed by EPMM, elevating risk for organizations using the product for mobile device management.

Technical discussion and community commentary amplified the disclosure, pointing to detailed research write-ups (including analysis focused on exploitation mechanics) and reinforcing the urgency of patching internet-exposed EPMM instances. Separate industry coverage during the same period also emphasized broader 2026 security priorities (AI-enabled social engineering, quantum-readiness, and general vulnerability management), but did not add incident-specific details about the Ivanti EPMM zero-days beyond the general call to improve patching discipline.

Share:
Ivanti Endpoint Manager Mobile Pre-Auth RCE Zero-Days (CVE-2026-1281, CVE-2026-1340)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 30, 20265mo ago

EU reports sharp rise in breach notifications and sustained GDPR enforcement

Late-January reporting said EU data breach notifications had risen 22%, averaging more than 400 per day, while GDPR fines in 2025 totaled about €1.2 billion. The increase came amid policy reform discussions tied to Digital Omnibus, NIS2, and DORA.

ShinyHunters-linked phishing and vishing hit multiple U.S. companies

Employees at several U.S. companies were targeted in phishing and vishing attacks, with ShinyHunters claiming responsibility and issuing extortion demands. The activity highlighted continued reliance on social engineering for initial access and pressure tactics.

Cyble discloses ShadowHS Linux post-exploitation framework

Cyble reported on ShadowHS, a stealthy fileless in-memory Linux post-exploitation framework that uses AES-encrypted payloads and memory execution to evade detection. The tooling was described as supporting credential theft, lateral movement, privilege escalation, cryptomining, and data exfiltration.

Cyberattack disrupts Delta alarm and vehicle security services

Delta, a Russian alarm and vehicle security provider, suffered a major cyberattack that disrupted services for tens of thousands of customers. The company said there was no confirmed customer data breach, though an unverified leaked dataset was reportedly circulating online.

CISA adds CVE-2026-1281 to KEV and orders rapid federal remediation

CISA added CVE-2026-1281 to its Known Exploited Vulnerabilities catalog and gave U.S. federal civilian agencies a two-day deadline to remediate. This indicated active exploitation serious enough to trigger urgent government action.

Ivanti releases emergency patches for two EPMM zero-days

Ivanti issued emergency fixes for two critical pre-authentication code injection vulnerabilities in Endpoint Manager Mobile, tracked as CVE-2026-1281 and CVE-2026-1340. The flaws were described as zero-days affecting EPMM deployments.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

36 LINKEDOpen in app
Threat actors
3 linked
Malware
1 linked
Affected products
2 linked
LinkedinImessage
Organizations
28 linked
GoogleLinkedinCybleCovewareKT CorporationDelta Air LinesSectigoCloudflareDark ReadingOmdiaNCC GroupIvantiBlackberryF5DeepwatchAppleCoupangThe Cyber ExpressEneaBumbleMerlin VenturesLG UplusCrunchbaseMatch GroupPaneramFilterItAlteraMastin & Associates
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.