CVE detail
CVE-2026-1281
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
21 source links · newest first
task. Figure 1. Autonomous attack flow observed in Hermes Agent session (May 7, 2026). Phase 1: Langflow Exploitation (CVE-2026-33017) DeepSeek identified a Langflow vulnerability ( CVE-2026-33017 , CVSS 9.8) and autonomously attempted exploitation through the following steps: Downloading the public PoC exploit from GitHub Enumerating 84 Langflow inst
vendorunit42.paloaltonetworks.comJul 30, 2026, 10:00 AMIvanti has released fixes for 5 high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) solution, one of which (CVE-2026-6973) has being exploited as a zero-day by attackers. “We are aware of a very limited number of customers exploited with CVE-2026-6973,” the company said in a security advisory published on Thursday. About CVE-2026-6973 CVE-2026-6973 is caused by improper input validation and allows remote attackers with administrative privileges to execute arbitrary code on vulnerable instances. “If customers … More →
newswww.helpnetsecurity.comMay 8, 2026, 10:30 AMCVE-2026-6973 is a high-severity vulnerability that allows an attacker who has admin privileges to execute arbitrary code.
newswww.securityweek.comMay 8, 2026, 5:41 AMAttackers are actively exploiting two critical zero-day vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) to gain unauthenticated control of enterprise mobile device management infrastructure and install backdoors engineered to persist even after organizations apply available patches. “Two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) affecting Ivanti Endpoint Manager Mobile (EPMM) are being actively exploited in the wild, affecting […]
newswww.csoonline.comFeb 23, 2026, 10:32 AMSecurity researchers have seen the vulnerabilities being exploited to deliver shells, conduct reconnaissance, and download malware.
newswww.securityweek.comFeb 19, 2026, 11:56 AMWe discuss widespread exploitation of Ivanti EPMM zero-day vulns CVE-2026-1281 and CVE-2026-1340. Attackers are deploying web shells and backdoors.
vendorunit42.paloaltonetworks.comFeb 17, 2026, 8:35 PM- Week in review: Exploited newly patched BeyondTrust RCE, United Airlines CISO on building resilienceHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: United Airlines CISO on building resilience when disruption is inevitable In this Help Net Security interview, Deneen DeFiore, VP and CISO at United Airlines, explains how the company approaches modernization without compromising safety-critical environments, why resilience and continuity matter as much as prevention, and how the airline manages risk across an interconnected ecosystem of vendors, partners, and infrastructure providers. What … More →
newswww.helpnetsecurity.comFeb 15, 2026, 9:00 AM - CVE-2026-1281 & CVE-2026-1340Horizon3.ai
Ivanti Endpoint Manager Mobile | Actively Exploited Remote Code Execution
exploithorizon3.aiFeb 11, 2026, 9:55 PM - Ivanti EPMM exploitation: Researchers warn of “sleeper” webshellsHelp Net Security
A massive wave of exploitation attempts has followed the disclosure of CVE-2026-1281, a critical pre-authentication Ivanti EPMM vulnerability, the Shadowserver Foundation has warned. Some of it is automated scanning for vulnerable systems, but according to Greynoise and Defused, a suspected initial access broker has been prepping unpatched instances with a “sleeper” webshell for follow-on exploitation by other threat actors. “On February 9, Defused Cyber reported a campaign deploying dormant in-memory Java class loaders to compromised … More →
newswww.helpnetsecurity.comFeb 11, 2026, 3:09 PM It also fixed a high-severity authentication bypass that could be exploited remotely without authentication to obtain credentials.
newswww.securityweek.comFeb 11, 2026, 12:14 PM- Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point ElsewhereGreyNoise
nvestigate for signs of compromise. For GreyNoise customers: An IOC package and executive situation report (SITREP) for CVE-2026-1281 have been delivered to your inbox. Check your email for the full package, including indicators, detection guidance, and a board-ready summary. The Vulnerability and Timeline CVE-2026-1281 is a CVSS 9.8 (v3.1) unauthen
vendorwww.greynoise.ioFeb 10, 2026, 12:00 AM The European Commission’s mobile device management platform was hacked but the incident was swiftly contained and no compromise of mobile devices was detected, EU’s executive branch announced on Friday. The intrusion was detected on January 30, 2026, by CERT-EU, the cybersecurity team protecting all European Union institutions, bodies, and agencies. “The Commission’s swift response ensured the incident was contained and the system cleaned within 9 hours,” the EC stated, and added that the intrusion “may … More →
newswww.helpnetsecurity.comFeb 9, 2026, 2:02 PM- 9th February – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 9th February, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Romania’s national oil pipeline operator, Conpet, has suffered a cyberattack that disrupted its IT systems and took its website offline. The company said operational technology, including pipeline control and telecommunications systems, remained […]
vendorresearch.checkpoint.comFeb 9, 2026, 12:50 PM - Week in review: Microsoft fixes exploited Office zero-day, Fortinet patches FortiCloud SSO flawHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: When open science meets real-world cybersecurity In this Help Net Security interview, Matthew Kwiatkowski, CISO at Fermilab, America’s particle physics and accelerator laboratory, discusses where cybersecurity blind spots emerge, why availability can outweigh confidentiality, and how security teams protect complex, legacy-driven research infrastructure while supporting scientific progress. Inside Microsoft’s veteran-to-tech workforce pipeline In this Help Net Security interview, Chris Cortez, … More →
newswww.helpnetsecurity.comFeb 1, 2026, 9:00 AM IT software company Ivanti released patches for its Endpoint Manager Mobile (EPMM) product to fix two new remote code execution vulnerabilities already under attack in the wild. “We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure,” the company said in a security advisory that […]
newswww.csoonline.comJan 30, 2026, 10:06 PM- Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)watchTowr Labs
When Ivanti removed the embargoes from CVE-2026-1281 and CVE-2026-1340 - actively exploited pre-auth Remote Command Execution vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) solution - we sighed with relief. Clearly, the universe had decided to continue mocking
exploitlabs.watchtowr.comJan 30, 2026, 4:15 PM The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Ivanti EPMM vulnerability, tracked as CVE-2026-1281 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is a code injection that impacts Ivanti Endpoint Manager […]
newssecurityaffairs.comJan 30, 2026, 10:40 AM- Ivanti Patches Exploited EPMM Zero-DaysSecurityWeek
The critical-severity vulnerabilities could allow unauthenticated attackers to execute arbitrary code remotely.
newswww.securityweek.comJan 30, 2026, 8:32 AM - Ivanti provides temporary patches for actively exploited EPMM zero-day (CVE-2026-1281)Help Net Security
Ivanti has released provisional patches that fix two critical code injection vulnerabilities in Endpoint Manager Mobile (EPMM), one of which (CVE-2026-1281) has been exploited in zero-day attacks and has been added to CISA’s Known Exploited Vulnerabilities catalog. Investigating potential compromise Both CVE-2026-1281 and CVE-2026-1340 are code injection flaws affecting EPMM’s In-House Application Distribution and Android File Transfer Configuration features. They may allow unauthenticated attackers to achieve remote code execution (RCE) on vulnerable on-premises EPMM installations. … More →
newswww.helpnetsecurity.comJan 30, 2026, 2:52 AM No excerpt available.
Mitigationwww.cisa.govJan 29, 2026, 10:15 PM- https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340forums.ivanti.com
No excerpt available.
Exploitforums.ivanti.comJan 29, 2026, 10:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-1340CVSS 9.8 · Critical
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
- CVE-2025-4428CVSS 7.2 · High
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via c…
- CVE-2026-0298CVSS 5.2 · Medium
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which e…
- CVE-2026-13094CVSS 7.8 · High
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration fi…
- CVE-2026-73268CVSS 9.9 · Critical
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arb…
- CVE-2026-73299CVSS 10.0 · Critical
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with u…