Critical Ivanti EPMM RCE Flaws Exploited to Compromise On-Premises Servers
Ivanti warned that its on-premises Endpoint Manager Mobile (EPMM) product contains two critical vulnerabilities, CVE-2026-1281 and CVE-2026-1340, that can let an unauthenticated remote attacker execute arbitrary commands or code over the network. The flaws affect exposed EPMM servers and create a path to full server compromise and possible lateral movement into internal environments. Ivanti said its cloud offerings, including Ivanti Neurons for MDM, and the separate Ivanti Endpoint Manager (EPM) product are not affected, and it released patches, incident-response guidance, and a detection tool to help customers assess exposure and compromise.
Follow-up advisories said the vulnerabilities are being actively exploited, prompting defenders to inspect EPMM systems for anomalous logs, unauthorized administrator-account changes, and suspicious device-configuration modifications. A later update citing Germany's BSI said exploitation may date back to summer 2025, expanding the scope of required forensic review beyond recent activity. Public reporting from security researchers, including Palo Alto Networks Unit 42 and vulnerability tracking sources, reinforced that the issue is an unauthenticated remote code execution risk requiring immediate patching and retrospective compromise hunting on affected on-premises deployments.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
8 events from the most recent confirmed update back to the earliest known activity.
Unit 42 reports critical Ivanti EPMM vulnerabilities are being exploited
Palo Alto Networks Unit 42 published reporting that the critical Ivanti EPMM vulnerabilities were under active exploitation. This reinforced public awareness of the in-the-wild abuse of the flaws.
German BSI report links Ivanti EPMM exploitation to 2025 activity
A February update cited a German BSI report saying exploitation had already taken place as early as summer 2025. Based on that finding, defenders were urged to review historical evidence of compromise rather than only recent activity.
Ivanti publishes and updates compromise assessment tooling
Ivanti published incident investigation guidance and a detection tool to help customers assess whether EPMM servers had been compromised. The tool was later updated to improve compromise assessment support.
Active exploitation warning added for Ivanti EPMM flaws
An update to the security notice stated that attackers were actively exploiting CVE-2026-1281 and CVE-2026-1340 in the wild. Defenders were advised to inspect EPMM devices for signs of compromise, including anomalous logs and unauthorized changes to admin accounts or device configuration.
watchTowr publishes PoC exploit for Ivanti EPMM flaws
On January 30, 2026, watchTowr Labs released a technical report with proof-of-concept exploit code for CVE-2026-1281 and CVE-2026-1340. The publication increased urgency for defenders to patch Ivanti EPMM systems and review logs for signs of compromise.
Traficom warns organizations to patch vulnerable Ivanti EPMM systems
Finland's Traficom issued a security notice warning that the Ivanti EPMM vulnerabilities were critical and required immediate patching. The notice clarified that Ivanti cloud products such as Ivanti Neurons for MDM and the separate Ivanti Endpoint Manager product were not affected.
Ivanti discloses critical EPMM flaws and issues patch guidance
Ivanti disclosed critical vulnerabilities affecting on-premises Endpoint Manager Mobile, including CVE-2026-1281 and CVE-2026-1340, and published guidance to patch affected systems. The flaws could allow unauthenticated remote command or code execution against the EPMM server.
Ivanti EPMM vulnerabilities were exploited as early as summer 2025
A later-cited German BSI report said exploitation of the Ivanti Endpoint Manager Mobile flaws had already occurred by summer 2025. This indicates the vulnerabilities were being abused well before public disclosure.
Sources
15 references tracked. Mallory keeps watching after this page renders.
Critical Vulnerabilities in Ivanti EPMM Exploited
unit42.paloaltonetworks.com
Open sourceBSI - Bundesamt für Sicherheit in der Informationstechnik - Version 1.3: Ivanti EPMM - Aktive Angriffe über Zero-Day Schwachstellen beobachtet
bsi.bund.de
Open sourceCasus: kwetsbaarheden Ivanti EPMM systemen | NCSC
ncsc.nl
Open sourceUpdate: geüpdatet scanscript beschikbaar voor kwetsbaarheid in Ivanti Endpoint Manager Mobile | NCSC
ncsc.nl
Open sourceIvanti EPMM Unauthenticated RCE (CVE-2026-1281) - TheHackerWire
thehackerwire.com
Open sourceIvanti EMM Unauthenticated RCE (CVE-2026-1340) - TheHackerWire
thehackerwire.com
Open sourceIvanti Endpoint Manager Mobile Exploit Chain Exploited in the Wild | Rapid7 Blog
rapid7.com
Open sourceIvanti Endpoint Manager Mobile - Unauthenticated Remote Code Execution
cloud.projectdiscovery.io
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


