Skip to main content
See every side of every news story
Published loading...Updated

Ivanti's January Bad Luck Continues as 0-Days Hit Customers

Ivanti released patches for two critical zero-day flaws rated 9.8 CVSS, enabling remote code execution and data access on on-premises EPMM appliances.

  • This year, Ivanti released RPM hotfix scripts for two critical EPMM zero-days and urged administrators and customers to apply them soon with no downtime.
  • Security notices say the flaws involve CVE-2026-1281 and CVE-2026-1340, code-injection bugs in Ivanti Endpoint Manager Mobile triggered via In‑House Application Distribution and Android File Transfer Configuration with exploits logged in Apache access log .
  • The flaws are rated CVSS 9.8, enabling attackers to access administrator and user account data, device identifiers, and execute arbitrary code on Ivanti Endpoint Manager Mobile.
  • CISA confirmed active exploitation by adding CVE-2026-1281 to its Known Exploited Vulnerabilities catalog, and federal civilian agencies must apply mitigations or discontinue vulnerable systems by February 1, 2026 under Binding Operational Directive 22-01.
  • If you suspect compromise, restore from a known-good backup or rebuild, and review GET requests with bash commands using the Ivanti detection regex, as hotfixes do not survive upgrades before version 12.8.0.0.
Insights by Ground AI

13 Articles

Global Security Mag OnlineGlobal Security Mag Online
Reposted by
Global Security Mag OnlineGlobal Security Mag Online

Multiple vulnerabilities have been discovered in Ivanti Endpoint Manager Mobile (EPMM). They allow an attacker to cause arbitrary code execution at a distance. Ivanti indicates that CVE-2026-1281 and CVE-2026-1340 vulnerabilities are actively exploited within the framework of... See online: https://www.cert.ssi.gouv.fr/avis/C...

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in on Thursday, January 29, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal