Ivanti’s EPMM is under active attack, thanks to two critical zero-days

Cybersecurity

Attackers are again focusing on a familiar target in the network edge space, actively exploiting two critical zero-day vulnerabilities in Ivanti software that allows administrators to set mobile device and application controls.  The vulnerabilities — CVE-2026-1281 and CVE-2026-1340 — each carry a CVSS rating of 9.8 and allow unauthenticated users to execute code remotely in Ivanti Endpoint Manager Mobile (EPMM). Ivanti did not say when the earliest known date of exploitation occurred but warned

Ivanti’s EPMM is under active attack, thanks to two critical zero-days https://www.cyberscoop.com - 03.02.2026 00:10

din zilele anterioare

Ivanti’s EPMM is under active attack, thanks to two critical zero-days https://www.cyberscoop.com - 03.02.2026 00:10