Skip to main content

CVE detail

CVE-2026-1340

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

CVSS 9.8 · CriticalBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
21 evidence mentions in the snapshot
Diversity score
20.0
11 sources across 5 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
1
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
21 source links · newest first
  • task. Figure 1. Autonomous attack flow observed in Hermes Agent session (May 7, 2026). Phase 1: Langflow Exploitation (CVE-2026-33017) DeepSeek identified a Langflow vulnerability ( CVE-2026-33017 , CVSS 9.8) and autonomously attempted exploitation through the following steps: Downloading the public PoC exploit from GitHub Enumerating 84 Langflow inst

    vendorunit42.paloaltonetworks.comJul 30, 2026, 10:00 AM
  • Attackers are exploiting the critical CVE-2026-10520 flaw in Ivanti Sentry, compromising many internet-exposed gateways shortly after patches were released. Threat actors have started exploiting a maximum-severity OS command injection flaw in Ivanti Sentry, tracked as CVE-2026-10520, that allows remote code execution with root privileges. “An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote […]

    newssecurityaffairs.comJun 11, 2026, 5:57 PM
  • Ivanti has released fixes for 5 high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) solution, one of which (CVE-2026-6973) has being exploited as a zero-day by attackers. “We are aware of a very limited number of customers exploited with CVE-2026-6973,” the company said in a security advisory published on Thursday. About CVE-2026-6973 CVE-2026-6973 is caused by improper input validation and allows remote attackers with administrative privileges to execute arbitrary code on vulnerable instances. “If customers … More →

    newswww.helpnetsecurity.comMay 8, 2026, 10:30 AM
  • CVE-2026-6973 is a high-severity vulnerability that allows an attacker who has admin privileges to execute arbitrary code.

    newswww.securityweek.comMay 8, 2026, 5:41 AM
  • 13th April – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 13th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The Los Angeles Police Department has reported a data breach involving a digital storage system used by the L.A. City Attorney’s Office. The exposure included 7.7 terabytes and more than 337,000 files, […]

    vendorresearch.checkpoint.comApr 13, 2026, 1:11 PM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in Ivanti EPMM, tracked as CVE-2026-1340 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The critical vulnerability is a code injection in Ivanti Endpoint Manager Mobile […]

    newssecurityaffairs.comApr 8, 2026, 9:35 PM
  • Attackers are actively exploiting two critical zero-day vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) to gain unauthenticated control of enterprise mobile device management infrastructure and install backdoors engineered to persist even after organizations apply available patches. “Two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) affecting Ivanti Endpoint Manager Mobile (EPMM) are being actively exploited in the wild, affecting […]

    newswww.csoonline.comFeb 23, 2026, 10:32 AM
  • Security researchers have seen the vulnerabilities being exploited to deliver shells, conduct reconnaissance, and download malware.

    newswww.securityweek.comFeb 19, 2026, 11:56 AM
  • We discuss widespread exploitation of Ivanti EPMM zero-day vulns CVE-2026-1281 and CVE-2026-1340. Attackers are deploying web shells and backdoors.

    vendorunit42.paloaltonetworks.comFeb 17, 2026, 8:35 PM
  • CVE-2026-1281 & CVE-2026-1340Horizon3.ai

    Ivanti Endpoint Manager Mobile | Actively Exploited Remote Code Execution

    exploithorizon3.aiFeb 11, 2026, 9:55 PM
  • A massive wave of exploitation attempts has followed the disclosure of CVE-2026-1281, a critical pre-authentication Ivanti EPMM vulnerability, the Shadowserver Foundation has warned. Some of it is automated scanning for vulnerable systems, but according to Greynoise and Defused, a suspected initial access broker has been prepping unpatched instances with a “sleeper” webshell for follow-on exploitation by other threat actors. “On February 9, Defused Cyber reported a campaign deploying dormant in-memory Java class loaders to compromised … More →

    newswww.helpnetsecurity.comFeb 11, 2026, 3:09 PM
  • It also fixed a high-severity authentication bypass that could be exploited remotely without authentication to obtain credentials.

    newswww.securityweek.comFeb 11, 2026, 12:14 PM
  • nvestigate for signs of compromise. For GreyNoise customers: An IOC package and executive situation report (SITREP) for CVE-2026-1281 have been delivered to your inbox. Check your email for the full package, including indicators, detection guidance, and a board-ready summary. ‍ The Vulnerability and Timeline CVE-2026-1281 is a CVSS 9.8 (v3.1) unauthen

    vendorwww.greynoise.ioFeb 10, 2026, 12:00 AM
  • The European Commission’s mobile device management platform was hacked but the incident was swiftly contained and no compromise of mobile devices was detected, EU’s executive branch announced on Friday. The intrusion was detected on January 30, 2026, by CERT-EU, the cybersecurity team protecting all European Union institutions, bodies, and agencies. “The Commission’s swift response ensured the incident was contained and the system cleaned within 9 hours,” the EC stated, and added that the intrusion “may … More →

    newswww.helpnetsecurity.comFeb 9, 2026, 2:02 PM
  • 9th February – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 9th February, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Romania’s national oil pipeline operator, Conpet, has suffered a cyberattack that disrupted its IT systems and took its website offline. The company said operational technology, including pipeline control and telecommunications systems, remained […]

    vendorresearch.checkpoint.comFeb 9, 2026, 12:50 PM
  • IT software company Ivanti released patches for its Endpoint Manager Mobile (EPMM) product to fix two new remote code execution vulnerabilities already under attack in the wild. “We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure,” the company said in a security advisory that […]

    newswww.csoonline.comJan 30, 2026, 10:06 PM
  • When Ivanti removed the embargoes from CVE-2026-1281 and CVE-2026-1340 - actively exploited pre-auth Remote Command Execution vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) solution - we sighed with relief. Clearly, the universe had decided to continue mocking

    exploitlabs.watchtowr.comJan 30, 2026, 4:15 PM
  • The critical-severity vulnerabilities could allow unauthenticated attackers to execute arbitrary code remotely.

    newswww.securityweek.comJan 30, 2026, 8:32 AM
  • Ivanti has released provisional patches that fix two critical code injection vulnerabilities in Endpoint Manager Mobile (EPMM), one of which (CVE-2026-1281) has been exploited in zero-day attacks and has been added to CISA’s Known Exploited Vulnerabilities catalog. Investigating potential compromise Both CVE-2026-1281 and CVE-2026-1340 are code injection flaws affecting EPMM’s In-House Application Distribution and Android File Transfer Configuration features. They may allow unauthenticated attackers to achieve remote code execution (RCE) on vulnerable on-premises EPMM installations. … More →

    newswww.helpnetsecurity.comJan 30, 2026, 2:52 AM
  • No excerpt available.

    Mitigationwww.cisa.govJan 29, 2026, 10:15 PM
  • No excerpt available.

    Exploitforums.ivanti.comJan 29, 2026, 10:15 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-1281

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    CVSS 9.8 · Critical
    KEV listed21 mentions
  • CVE-2025-4428

    Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via c…

    CVSS 7.2 · High
    KEV listed19 mentions
  • CVE-2026-72676

    Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Ki…

    CVSS 6.5 · Medium
    1 mention
  • CVE-2026-73651

    TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases. Prior to versions 0.3.31 and 1.1.…

    CVSS 5.7 · Medium
    5 mentions
  • CVE-2026-73649

    Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototyp…

    CVSS 9.8 · Critical
    4 mentions
  • CVE-2026-73505

    Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which i…

    CVSS 7.8 · High
    4 mentions