CVE detail
CVE-2026-1340
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
21 source links · newest first
task. Figure 1. Autonomous attack flow observed in Hermes Agent session (May 7, 2026). Phase 1: Langflow Exploitation (CVE-2026-33017) DeepSeek identified a Langflow vulnerability ( CVE-2026-33017 , CVSS 9.8) and autonomously attempted exploitation through the following steps: Downloading the public PoC exploit from GitHub Enumerating 84 Langflow inst
vendorunit42.paloaltonetworks.comJul 30, 2026, 10:00 AM- CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch ReleaseSecurity Affairs
Attackers are exploiting the critical CVE-2026-10520 flaw in Ivanti Sentry, compromising many internet-exposed gateways shortly after patches were released. Threat actors have started exploiting a maximum-severity OS command injection flaw in Ivanti Sentry, tracked as CVE-2026-10520, that allows remote code execution with root privileges. “An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote […]
newssecurityaffairs.comJun 11, 2026, 5:57 PM Ivanti has released fixes for 5 high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) solution, one of which (CVE-2026-6973) has being exploited as a zero-day by attackers. “We are aware of a very limited number of customers exploited with CVE-2026-6973,” the company said in a security advisory published on Thursday. About CVE-2026-6973 CVE-2026-6973 is caused by improper input validation and allows remote attackers with administrative privileges to execute arbitrary code on vulnerable instances. “If customers … More →
newswww.helpnetsecurity.comMay 8, 2026, 10:30 AMCVE-2026-6973 is a high-severity vulnerability that allows an attacker who has admin privileges to execute arbitrary code.
newswww.securityweek.comMay 8, 2026, 5:41 AM- 13th April – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 13th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The Los Angeles Police Department has reported a data breach involving a digital storage system used by the L.A. City Attorney’s Office. The exposure included 7.7 terabytes and more than 337,000 files, […]
vendorresearch.checkpoint.comApr 13, 2026, 1:11 PM The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in Ivanti EPMM, tracked as CVE-2026-1340 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The critical vulnerability is a code injection in Ivanti Endpoint Manager Mobile […]
newssecurityaffairs.comApr 8, 2026, 9:35 PMAttackers are actively exploiting two critical zero-day vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) to gain unauthenticated control of enterprise mobile device management infrastructure and install backdoors engineered to persist even after organizations apply available patches. “Two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) affecting Ivanti Endpoint Manager Mobile (EPMM) are being actively exploited in the wild, affecting […]
newswww.csoonline.comFeb 23, 2026, 10:32 AMSecurity researchers have seen the vulnerabilities being exploited to deliver shells, conduct reconnaissance, and download malware.
newswww.securityweek.comFeb 19, 2026, 11:56 AMWe discuss widespread exploitation of Ivanti EPMM zero-day vulns CVE-2026-1281 and CVE-2026-1340. Attackers are deploying web shells and backdoors.
vendorunit42.paloaltonetworks.comFeb 17, 2026, 8:35 PM- CVE-2026-1281 & CVE-2026-1340Horizon3.ai
Ivanti Endpoint Manager Mobile | Actively Exploited Remote Code Execution
exploithorizon3.aiFeb 11, 2026, 9:55 PM - Ivanti EPMM exploitation: Researchers warn of “sleeper” webshellsHelp Net Security
A massive wave of exploitation attempts has followed the disclosure of CVE-2026-1281, a critical pre-authentication Ivanti EPMM vulnerability, the Shadowserver Foundation has warned. Some of it is automated scanning for vulnerable systems, but according to Greynoise and Defused, a suspected initial access broker has been prepping unpatched instances with a “sleeper” webshell for follow-on exploitation by other threat actors. “On February 9, Defused Cyber reported a campaign deploying dormant in-memory Java class loaders to compromised … More →
newswww.helpnetsecurity.comFeb 11, 2026, 3:09 PM It also fixed a high-severity authentication bypass that could be exploited remotely without authentication to obtain credentials.
newswww.securityweek.comFeb 11, 2026, 12:14 PM- Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point ElsewhereGreyNoise
nvestigate for signs of compromise. For GreyNoise customers: An IOC package and executive situation report (SITREP) for CVE-2026-1281 have been delivered to your inbox. Check your email for the full package, including indicators, detection guidance, and a board-ready summary. The Vulnerability and Timeline CVE-2026-1281 is a CVSS 9.8 (v3.1) unauthen
vendorwww.greynoise.ioFeb 10, 2026, 12:00 AM The European Commission’s mobile device management platform was hacked but the incident was swiftly contained and no compromise of mobile devices was detected, EU’s executive branch announced on Friday. The intrusion was detected on January 30, 2026, by CERT-EU, the cybersecurity team protecting all European Union institutions, bodies, and agencies. “The Commission’s swift response ensured the incident was contained and the system cleaned within 9 hours,” the EC stated, and added that the intrusion “may … More →
newswww.helpnetsecurity.comFeb 9, 2026, 2:02 PM- 9th February – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 9th February, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Romania’s national oil pipeline operator, Conpet, has suffered a cyberattack that disrupted its IT systems and took its website offline. The company said operational technology, including pipeline control and telecommunications systems, remained […]
vendorresearch.checkpoint.comFeb 9, 2026, 12:50 PM IT software company Ivanti released patches for its Endpoint Manager Mobile (EPMM) product to fix two new remote code execution vulnerabilities already under attack in the wild. “We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure,” the company said in a security advisory that […]
newswww.csoonline.comJan 30, 2026, 10:06 PM- Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)watchTowr Labs
When Ivanti removed the embargoes from CVE-2026-1281 and CVE-2026-1340 - actively exploited pre-auth Remote Command Execution vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) solution - we sighed with relief. Clearly, the universe had decided to continue mocking
exploitlabs.watchtowr.comJan 30, 2026, 4:15 PM - Ivanti Patches Exploited EPMM Zero-DaysSecurityWeek
The critical-severity vulnerabilities could allow unauthenticated attackers to execute arbitrary code remotely.
newswww.securityweek.comJan 30, 2026, 8:32 AM - Ivanti provides temporary patches for actively exploited EPMM zero-day (CVE-2026-1281)Help Net Security
Ivanti has released provisional patches that fix two critical code injection vulnerabilities in Endpoint Manager Mobile (EPMM), one of which (CVE-2026-1281) has been exploited in zero-day attacks and has been added to CISA’s Known Exploited Vulnerabilities catalog. Investigating potential compromise Both CVE-2026-1281 and CVE-2026-1340 are code injection flaws affecting EPMM’s In-House Application Distribution and Android File Transfer Configuration features. They may allow unauthenticated attackers to achieve remote code execution (RCE) on vulnerable on-premises EPMM installations. … More →
newswww.helpnetsecurity.comJan 30, 2026, 2:52 AM No excerpt available.
Mitigationwww.cisa.govJan 29, 2026, 10:15 PM- https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340forums.ivanti.com
No excerpt available.
Exploitforums.ivanti.comJan 29, 2026, 10:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-1281CVSS 9.8 · Critical
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
- CVE-2025-4428CVSS 7.2 · High
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via c…
- CVE-2026-72676CVSS 6.5 · Medium
Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Ki…
- CVE-2026-73651CVSS 5.7 · Medium
TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases. Prior to versions 0.3.31 and 1.1.…
- CVE-2026-73649CVSS 9.8 · Critical
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototyp…
- CVE-2026-73505CVSS 7.8 · High
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which i…