Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitywidely-deployed-product-advisoryinternet-facing-service-vulnerabilitydetection-content-update

Critical Ivanti EPMM RCE Flaws Exploited to Compromise On-Premises Servers

Updated 29d agoFirst seen May 25, 202615 sources

Ivanti warned that its on-premises Endpoint Manager Mobile (EPMM) product contains two critical vulnerabilities, CVE-2026-1281 and CVE-2026-1340, that can let an unauthenticated remote attacker execute arbitrary commands or code over the network. The flaws affect exposed EPMM servers and create a path to full server compromise and possible lateral movement into internal environments. Ivanti said its cloud offerings, including Ivanti Neurons for MDM, and the separate Ivanti Endpoint Manager (EPM) product are not affected, and it released patches, incident-response guidance, and a detection tool to help customers assess exposure and compromise.

Follow-up advisories said the vulnerabilities are being actively exploited, prompting defenders to inspect EPMM systems for anomalous logs, unauthorized administrator-account changes, and suspicious device-configuration modifications. A later update citing Germany's BSI said exploitation may date back to summer 2025, expanding the scope of required forensic review beyond recent activity. Public reporting from security researchers, including Palo Alto Networks Unit 42 and vulnerability tracking sources, reinforced that the issue is an unauthenticated remote code execution risk requiring immediate patching and retrospective compromise hunting on affected on-premises deployments.

Share:
Critical Ivanti EPMM RCE Flaws Exploited to Compromise On-Premises Servers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Feb 17, 20264mo ago

Unit 42 reports critical Ivanti EPMM vulnerabilities are being exploited

Palo Alto Networks Unit 42 published reporting that the critical Ivanti EPMM vulnerabilities were under active exploitation. This reinforced public awareness of the in-the-wild abuse of the flaws.

Feb 13, 20264mo ago

German BSI report links Ivanti EPMM exploitation to 2025 activity

A February update cited a German BSI report saying exploitation had already taken place as early as summer 2025. Based on that finding, defenders were urged to review historical evidence of compromise rather than only recent activity.

Feb 9, 20264mo ago

Ivanti publishes and updates compromise assessment tooling

Ivanti published incident investigation guidance and a detection tool to help customers assess whether EPMM servers had been compromised. The tool was later updated to improve compromise assessment support.

Active exploitation warning added for Ivanti EPMM flaws

An update to the security notice stated that attackers were actively exploiting CVE-2026-1281 and CVE-2026-1340 in the wild. Defenders were advised to inspect EPMM devices for signs of compromise, including anomalous logs and unauthorized changes to admin accounts or device configuration.

Jan 30, 20265mo ago

watchTowr publishes PoC exploit for Ivanti EPMM flaws

On January 30, 2026, watchTowr Labs released a technical report with proof-of-concept exploit code for CVE-2026-1281 and CVE-2026-1340. The publication increased urgency for defenders to patch Ivanti EPMM systems and review logs for signs of compromise.

Ivanti Zero-Day Vulnerabilities (CVE-2026-1281, CVE-2026-1340) Disclosed | eSentire
Jan 29, 20265mo ago

Traficom warns organizations to patch vulnerable Ivanti EPMM systems

Finland's Traficom issued a security notice warning that the Ivanti EPMM vulnerabilities were critical and required immediate patching. The notice clarified that Ivanti cloud products such as Ivanti Neurons for MDM and the separate Ivanti Endpoint Manager product were not affected.

Ivanti discloses critical EPMM flaws and issues patch guidance

Ivanti disclosed critical vulnerabilities affecting on-premises Endpoint Manager Mobile, including CVE-2026-1281 and CVE-2026-1340, and published guidance to patch affected systems. The flaws could allow unauthenticated remote command or code execution against the EPMM server.

Ivanti EPMM vulnerabilities were exploited as early as summer 2025

A later-cited German BSI report said exploitation of the Ivanti Endpoint Manager Mobile flaws had already occurred by summer 2025. This indicates the vulnerabilities were being abused well before public disclosure.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.