Attackers are actively exploiting two critical zero-day vulnerabilities in Ivanti's Endpoint Manager Mobile (EPMM)to gain unauthorized infrastructure mobile device management and install backdoors designed to persist in the system, even after organizations apply available updates.

“ Two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) affecting Ivanti Endpoint Manager Mobile (EPMM) are being actively exploited by cybercriminals, affecting mobile devices and corporate networks ,” Palo Alto Networks’ Unit 42 threat research team reported
“These vulnerabilities allow unauthorized attackers to remotely execute arbitrary code on targeted servers, gaining complete control of the mobile device management (MDM) infrastructure without requiring user interaction or credentials.“.
See also: XMRig Wormable Campaign: New attack with BYOVD exploit
EPMM, formerly known as MobileIron Core, is a mobile device management platform that enterprises use to manage and enforce security policies smartphones and tablets employee
Palo Alto Networks' Cortex Xpanse platform has detected more than 4,400 EPMM instances exposed on the public internet.
Ivanti EPMM Vulnerabilities: High Risk for Organizations
A breach of the platform gives attackers access to device policies, credentials, and metadata across an organization’s entire mobile device fleet. Both vulnerabilities have a CVSS score of 9.8 and allow unauthorized attackers to execute arbitrary commands on exposed EPMM servers without any user interaction or valid credentials.
Ivanti acknowledged the attacks when it released emergency updates in late January, but initially described the impact as limited.

Both vulnerabilities stem from insecure handling of Bash scripts in old Apache web server configurations , according to Unit 42.
CVE -2026-1281 targets the In-House Application Distribution feature, while CVE-2026-1340 exploits the same class of flaw through a separate script that manages the Android File Transfer.
See also: APT28 targets Europe with webhook-based macro malware
“ Although the root of the problem is the same, they are located in two separate scripts that handle different functions ,” the advisory explained .
From scanning to backdoor
Unit 42 documented malicious actors moving quickly from automated scanning to initial access and then rapidly escalating their privileges to deploy persistent backdoors, designed to last beyond update cycles. After gaining initial access, the attackers immediately attempted to download and execute a second-stage payload.
“This second stage typically installs a web shell, cryptographer , or persistent backdoor to give the attacker control of the device,” the advisory said. Unit 42 also said the attackers deployed the open-source Nezha monitoring agent to maintain visibility into compromised systems.
The attackers targeted sectors such as state and local government, healthcare, manufacturing, professional services, and high technology in the United States, Germany, Australia, and Canada.
Unit 42 warned that proof-of-concept exploit code is available for both CVEs, making wider exploitation possible as more malicious actors adopt functional exploits.

Apply updates and verify
Unit 42 directed organizations to Ivanti's security advisory for remediation guidance. It is recommended to apply specific RPM updates for EPMM 12.x versions that do not require device downtime.
Ivanti warned, however, that the update does not survive a version upgrade and must be reinstalled if the software is updated.
“The permanent fix for this vulnerability will be included in the next product release: 12.8.0.0 expected in Q1 2026“.
Ivanti also warned that while the Sentry mobile traffic gateway is not directly vulnerable, EPMM has command execution rights on connected Sentry systems.
See also: Jenkins vulnerability exposes build environments to XSS attacks
“If an EPMM installation has been compromised, attackers may have also compromised Ivanti Sentry,” Ivanti warned.
Organizations that suspect a breach are urged not to attempt to clean up affected systems. Instead, they are advised to restore from a known good backup or perform a full rebuild, followed by a full reset of all account passwords, service credentials, and public certificates.
The targeting of EPMM follows a pattern familiar to Ivanti customers. The product has been exploited on a large scale in the past — in 2023, state-sponsored attackers used EPMM zero-days to penetrate Norwegian government, and separate flaws were exploited again last year.
Ivanti's Connect Secure VPN product also has a similarly problematic history, with Chinese APT groups exploiting zero-days in consecutive campaigns that ultimately led the US government to order federal agencies to decommission Ivanti's VPN products in February 2024.
