#ivanti-epmm

[ follow ]
fromTheregister
16 hours ago

Ivanti's January bad luck continues as 0-days hit customers

Tracked as CVE-2026-1281 and CVE-2026-1340, both bugs affect Ivanti Endpoint Manager Mobile (EPMM). They're also both rated a near-maximum CVSS score of 9.8 and allow for unauthenticated remote code execution (RCE) - about as bad as it gets. The security shop said in its advisory: "We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure.
Information security
fromSecurityWeek
1 day ago

Ivanti Patches Exploited EPMM Zero-Days

Ivanti on Thursday announced emergency patches for two critical-severity vulnerabilities in Endpoint Manager Mobile (EPMM) that have been exploited in the wild as zero-days. Tracked as CVE-2026-1281 and CVE-2026-1340 (CVSS score of 9.8), the bugs are described as code injection issues that could be exploited by unauthenticated attackers to achieve remote code execution (RCE). The flaws impact the in-house application distribution and the Android file transfer configuration features of EPMM.
Information security
Information security
fromThe Hacker News
1 day ago

Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Released

Two critical code-injection vulnerabilities (CVE-2026-1281 and CVE-2026-1340) enable unauthenticated remote code execution in Ivanti EPMM, exploited in zero-day attacks.
Information security
fromTheregister
4 months ago

CISA: Attacker exploited Ivanti bugs, dropped snoopy malware

Two zero-day Ivanti EPMM vulnerabilities (CVE-2025-4427, CVE-2025-4428) were chained to deploy malware and enable arbitrary code execution on compromised servers.
#cve-2025-4427
Information security
fromThe Hacker News
8 months ago

Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks

Ivanti Endpoint Manager Mobile vulnerabilities exploited by a China-based group pose significant risks across multiple sectors worldwide.
[ Load more ]