Skip to main content

CVE detail

CVE-2026-1281

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

CVSS 9.8 · CriticalBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
21 evidence mentions in the snapshot
Diversity score
20.0
11 sources across 5 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
1
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
21 source links · newest first
  • task. Figure 1. Autonomous attack flow observed in Hermes Agent session (May 7, 2026). Phase 1: Langflow Exploitation (CVE-2026-33017) DeepSeek identified a Langflow vulnerability ( CVE-2026-33017 , CVSS 9.8) and autonomously attempted exploitation through the following steps: Downloading the public PoC exploit from GitHub Enumerating 84 Langflow inst

    vendorunit42.paloaltonetworks.comJul 30, 2026, 10:00 AM
  • Ivanti has released fixes for 5 high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) solution, one of which (CVE-2026-6973) has being exploited as a zero-day by attackers. “We are aware of a very limited number of customers exploited with CVE-2026-6973,” the company said in a security advisory published on Thursday. About CVE-2026-6973 CVE-2026-6973 is caused by improper input validation and allows remote attackers with administrative privileges to execute arbitrary code on vulnerable instances. “If customers … More →

    newswww.helpnetsecurity.comMay 8, 2026, 10:30 AM
  • CVE-2026-6973 is a high-severity vulnerability that allows an attacker who has admin privileges to execute arbitrary code.

    newswww.securityweek.comMay 8, 2026, 5:41 AM
  • Attackers are actively exploiting two critical zero-day vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) to gain unauthenticated control of enterprise mobile device management infrastructure and install backdoors engineered to persist even after organizations apply available patches. “Two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) affecting Ivanti Endpoint Manager Mobile (EPMM) are being actively exploited in the wild, affecting […]

    newswww.csoonline.comFeb 23, 2026, 10:32 AM
  • Security researchers have seen the vulnerabilities being exploited to deliver shells, conduct reconnaissance, and download malware.

    newswww.securityweek.comFeb 19, 2026, 11:56 AM
  • We discuss widespread exploitation of Ivanti EPMM zero-day vulns CVE-2026-1281 and CVE-2026-1340. Attackers are deploying web shells and backdoors.

    vendorunit42.paloaltonetworks.comFeb 17, 2026, 8:35 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: United Airlines CISO on building resilience when disruption is inevitable In this Help Net Security interview, Deneen DeFiore, VP and CISO at United Airlines, explains how the company approaches modernization without compromising safety-critical environments, why resilience and continuity matter as much as prevention, and how the airline manages risk across an interconnected ecosystem of vendors, partners, and infrastructure providers. What … More →

    newswww.helpnetsecurity.comFeb 15, 2026, 9:00 AM
  • CVE-2026-1281 & CVE-2026-1340Horizon3.ai

    Ivanti Endpoint Manager Mobile | Actively Exploited Remote Code Execution

    exploithorizon3.aiFeb 11, 2026, 9:55 PM
  • A massive wave of exploitation attempts has followed the disclosure of CVE-2026-1281, a critical pre-authentication Ivanti EPMM vulnerability, the Shadowserver Foundation has warned. Some of it is automated scanning for vulnerable systems, but according to Greynoise and Defused, a suspected initial access broker has been prepping unpatched instances with a “sleeper” webshell for follow-on exploitation by other threat actors. “On February 9, Defused Cyber reported a campaign deploying dormant in-memory Java class loaders to compromised … More →

    newswww.helpnetsecurity.comFeb 11, 2026, 3:09 PM
  • It also fixed a high-severity authentication bypass that could be exploited remotely without authentication to obtain credentials.

    newswww.securityweek.comFeb 11, 2026, 12:14 PM
  • nvestigate for signs of compromise. For GreyNoise customers: An IOC package and executive situation report (SITREP) for CVE-2026-1281 have been delivered to your inbox. Check your email for the full package, including indicators, detection guidance, and a board-ready summary. ‍ The Vulnerability and Timeline CVE-2026-1281 is a CVSS 9.8 (v3.1) unauthen

    vendorwww.greynoise.ioFeb 10, 2026, 12:00 AM
  • The European Commission’s mobile device management platform was hacked but the incident was swiftly contained and no compromise of mobile devices was detected, EU’s executive branch announced on Friday. The intrusion was detected on January 30, 2026, by CERT-EU, the cybersecurity team protecting all European Union institutions, bodies, and agencies. “The Commission’s swift response ensured the incident was contained and the system cleaned within 9 hours,” the EC stated, and added that the intrusion “may … More →

    newswww.helpnetsecurity.comFeb 9, 2026, 2:02 PM
  • 9th February – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 9th February, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Romania’s national oil pipeline operator, Conpet, has suffered a cyberattack that disrupted its IT systems and took its website offline. The company said operational technology, including pipeline control and telecommunications systems, remained […]

    vendorresearch.checkpoint.comFeb 9, 2026, 12:50 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: When open science meets real-world cybersecurity In this Help Net Security interview, Matthew Kwiatkowski, CISO at Fermilab, America’s particle physics and accelerator laboratory, discusses where cybersecurity blind spots emerge, why availability can outweigh confidentiality, and how security teams protect complex, legacy-driven research infrastructure while supporting scientific progress. Inside Microsoft’s veteran-to-tech workforce pipeline In this Help Net Security interview, Chris Cortez, … More →

    newswww.helpnetsecurity.comFeb 1, 2026, 9:00 AM
  • IT software company Ivanti released patches for its Endpoint Manager Mobile (EPMM) product to fix two new remote code execution vulnerabilities already under attack in the wild. “We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure,” the company said in a security advisory that […]

    newswww.csoonline.comJan 30, 2026, 10:06 PM
  • When Ivanti removed the embargoes from CVE-2026-1281 and CVE-2026-1340 - actively exploited pre-auth Remote Command Execution vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) solution - we sighed with relief. Clearly, the universe had decided to continue mocking

    exploitlabs.watchtowr.comJan 30, 2026, 4:15 PM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Ivanti EPMM vulnerability, tracked as CVE-2026-1281 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is a code injection that impacts Ivanti Endpoint Manager […]

    newssecurityaffairs.comJan 30, 2026, 10:40 AM
  • The critical-severity vulnerabilities could allow unauthenticated attackers to execute arbitrary code remotely.

    newswww.securityweek.comJan 30, 2026, 8:32 AM
  • Ivanti has released provisional patches that fix two critical code injection vulnerabilities in Endpoint Manager Mobile (EPMM), one of which (CVE-2026-1281) has been exploited in zero-day attacks and has been added to CISA’s Known Exploited Vulnerabilities catalog. Investigating potential compromise Both CVE-2026-1281 and CVE-2026-1340 are code injection flaws affecting EPMM’s In-House Application Distribution and Android File Transfer Configuration features. They may allow unauthenticated attackers to achieve remote code execution (RCE) on vulnerable on-premises EPMM installations. … More →

    newswww.helpnetsecurity.comJan 30, 2026, 2:52 AM
  • No excerpt available.

    Mitigationwww.cisa.govJan 29, 2026, 10:15 PM
  • No excerpt available.

    Exploitforums.ivanti.comJan 29, 2026, 10:15 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-1340

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    CVSS 9.8 · Critical
    KEV listed21 mentions
  • CVE-2025-4428

    Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via c…

    CVSS 7.2 · High
    KEV listed19 mentions
  • CVE-2026-0298

    An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which e…

    CVSS 5.2 · Medium
    1 mention
  • CVE-2026-13094

    IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration fi…

    CVSS 7.8 · High
    1 mention
  • CVE-2026-73268

    A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arb…

    CVSS 9.9 · Critical
    2 mentions
  • CVE-2026-73299

    Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with u…

    CVSS 10.0 · Critical
    6 mentions