Skip to content
COOEY

EXPOSURES › CVE-2026-1340

CVE-2026-1340

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-04-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-1340 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildransomwaresupply-chain

Ivanti EPMM allows unauthenticated remote code execution via code injection, enabling attackers to compromise endpoint management systems without credentials.

This unauthenticated RCE vulnerability in Ivanti Endpoint Manager Mobile allows attackers to execute arbitrary code on managed endpoints without authentication, posing a severe risk to DIB organizations relying on endpoint management for security posture and compliance. The vulnerability is actively exploited in the wild and linked to ransomware campaigns, making it a critical priority for patching and network segmentation to prevent lateral movement.

Shame score — An unauthenticated RCE vulnerability in a widely deployed endpoint management product that is actively exploited in the wild represents a severe, avoidable security failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized