Skip to content
COOEY

EXPOSURES › CVE-2026-1281

CVE-2026-1281

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-01-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-1281 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 90/100 rceexploited-in-wildunpatched

Ivanti EPMM exposed to unauthenticated RCE due to code injection flaw

Ivanti's Endpoint Manager Mobile faced persistent attacks, breaching government agencies, due to unpatched code injection vulnerabilities exploited by Chinese actors.

Shame score — Repeatedly targeted by nation-state actors, leading to breaches at multiple government agencies.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized