Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

CVE-2026-1281 and 1340: active attacks on Ivanti EPMM

CVE-2026-1281 and CVE-2026-1340 enable unauthenticated RCE in Ivanti EPMM. Review advisory facts, KEV status and response steps.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
30 January 2026
READING TIME
9 min read
TOPIC
Vulnerabilities and CVEs
CVE-2026-1281 and 1340: active attacks on Ivanti EPMM

Information about two critical Ivanti Endpoint Manager Mobile (EPMM) vulnerabilities was published on 29 January 2026: CVE-2026-1281 and CVE-2026-1340. Both are code-injection flaws allowing unauthenticated remote code execution. Their CNA records assign CVSS 3.1 9.8 with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

CISA marks exploitation of both flaws as active. CVE-2026-1281 entered KEV on 29 January, while CVE-2026-1340 was added on 8 April 2026. That date distinction matters: the article should not imply simultaneous KEV inclusion.

Why it’s so dangerous

EPMM (formerly MobileIron Core) manages a company’s fleet of mobile devices. By its nature it’s often exposed to the internet so employees’ phones can connect from outside the network. That makes it an ideal target: it’s publicly reachable and has privileged access to devices and data.

There is no need to infer a separate authentication-bypass chain here: both official CVE descriptions directly state unauthenticated RCE. Potential impact spans confidentiality, integrity and availability, so an exposed affected server needs both remediation and compromise assessment.

Establishing exposure

The current Ivanti advisory is the source of truth for releases and patch packages. NVD records show broad EPMM version coverage, but vendor details can be refined. Rather than copying a static table, record version, build, package type, update date and public exposure for every instance, then compare with the advisory.

Include standby and disaster-recovery nodes, old post-migration systems, machine images and test environments containing production data. Review DNS, NAT, reverse proxies and firewall rules. The administrative interface may be hidden while another endpoint needed by mobile devices remains internet reachable.

What to do right now

  1. Obtain patches and instructions only from the Ivanti advisory and match them to the exact build.
  2. Preserve configuration and investigation logs before changing the system.
  3. Update active and standby nodes, then verify build and critical device-management workflows.
  4. Restrict administration interfaces to trusted paths while retaining only documented service exposure.
  5. If the instance was reachable during the vulnerable period, start compromise analysis rather than treating patch installation as incident closure.

Investigation and safe recovery

Preserve application, operating-system, proxy, WAF, EDR and authentication logs. Build a timeline from the first affected release through verified patch deployment. Review accounts, configuration, processes, services, scheduled tasks, files and outbound connections. Use current Ivanti integrity tools and indicators, but do not reduce the investigation to one IOC.

A mobile-management server may store or reach credentials, certificates and tokens for other systems. Where evidence confirms compromise, inventory those dependencies, revoke exposed secrets and monitor attempts to reuse them. Rebuilding from a trusted image with controlled configuration restoration can be safer than retaining a manually cleaned server.

Closure evidence

The report should contain every instance, versions before and after, exposure period, log coverage, investigation result, rotations and a post-update functional test. Confirm that backup or automation cannot restore an affected image. Apply the same evidence model to the vulnerability-management process.

The broader lesson

Ivanti EPMM isn’t an isolated case — it’s part of a pattern in which edge appliances (VPNs, gateways, management servers) are the first line of attack. The takeaway is simple: an actively exploited vulnerability is urgent regardless of its CVSS score. That’s exactly what we cover in our piece on vulnerability prioritisation — presence in the KEV is the strongest signal to act immediately.

If you’re not sure whether your edge systems are up to date and properly segmented, get in touch — we’ll help set up a rapid-response process for critical flaws.


Sources: Ivanti — CVE-2026-1281 and CVE-2026-1340 advisory, NVD — CVE-2026-1281, NVD — CVE-2026-1340, CISA KEV.

SHARE / COPY