HomeSecurityIvanti EPMM: Exploiting zero-day vulnerabilities - UPDATE NOW

Ivanti EPMM: Exploiting zero-day vulnerabilities – UPDATE NOW

Ivanti has released security updates to address two vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM) that have been exploited in zero-day attacks . One of these vulnerabilities has also been added to the CISA Known Exploitable Vulnerabilities (KEV) list.

Ivanti EPMM zero-day

Ivanti: How vulnerabilities work and which versions they affect

– CVE-2026-1281 (CVSS score: 9.8) – Code injection vulnerability that allows attackers to achieve unauthorized remote code execution.

– CVE-2026-1340 (CVSS score: 9.8) – Code injection vulnerability that allows attackers to achieve unauthorized remote code execution.

These vulnerabilities affect EPMM versions 12.5.0.0 and earlier, 12.6.0.0 and earlier, and 12.7.0.0 and earlier (fixed in RPM 12.x.0.x). EPMM 12.5.1.0 and earlier and 12.6.1.0 and earlier (fixed in RPM 12.x.1.x) are also affected

See also: eScan: Compromised update server pushed malicious update

It is important to note that the RPM patch does not survive a version upgrade and must be reapplied if the device is upgraded to a new version. The vulnerabilities will be permanently addressed in EPMM version 12.8.0.0, which is scheduled to be released later, in the first quarter of 2026.

What does Ivanti say about the attacks?

Ivanti said in an advisory: “We are aware of a very limited number of customers affected at the time of disclosure,” adding that it does not have enough information about threat actors’ tactics to provide proven, reliable individual indicators.

The company noted that CVE-2026-1281 and CVE-2026-1340 affect the In-House Application Distribution and Android File Transfer Configuration features. These vulnerabilities do not affect other products, including Ivanti Neurons for MDM, Ivanti Endpoint Manager (EPM), or Ivanti Sentry.

Ivanti EPMM: Exploiting zero-day vulnerabilities - UPDATE NOW

In a technical analysis, Ivanti said it has observed mainly two forms of persistence based on previous attacks targeting older vulnerabilities in EPMM: deployment of webshells and reverse shells to install persistence on compromised devices.

See also: SolarWinds: Critical RCE vulnerabilities in Web Help Desk

“Successful exploitation of the EPMM device would allow arbitrary code execution on the device,” Ivanti noted. “In addition to lateral movement in the connected environment, the EPMM also contains sensitive information about the devices managed by the device.”

Users are urged to check the Apache access log at “/var/log/httpd/https-access_log” for signs of attempted or successful exploitation using the following regular expression (regex) pattern:

^(?!127\.0\.0\.1:\d+ .*$).*?\/mifs\/c\/(aft|app)store\/fob\/.*?404

“Legitimate use of these features will result in 200 HTTP response codes in the Apache Access Log, while a successful exploit or attempted exploit will result in 404 HTTP response codes.“.

What should customers check?

Additionally, customers are asked to review the following for any indication of unauthorized configuration changes:

– EPMM Administrators for new or recently changed administrators

– Authentication configuration, including SSO and LDAP settings

– New push applications for mobile devices

– Configuration changes to applications pushed to devices, including internal use applications

– New or recently modified policies

– Network configuration changes, including any network configuration or VPN configuration pushed to mobile devices

See also: vm2 Node.js: “sandbox escape” vulnerability allows code execution

Ivanti EPMM: Exploiting zero-day vulnerabilities - UPDATE NOW

In the event that signs of compromise are detected, Ivanti urges users to restore the EPMM appliance from a known good backup or set up a new EPMM appliance and then migrate the data to the appliance. Once these steps are complete, the following changes are necessary to secure the environment:

– Reset the password of any local EPMM accounts

– Reset the password for LDAP and/or KDC service accounts that perform searches

– Revoke and replace the public certificate used for your EPMM

– Reset the password for any other internal or external service accounts configured with the EPMM solution

This development has prompted CISA to add CVE-2026-1281 to the KEV list, requiring FCEB Federal Services to implement the updates by February 1, 2026.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS