Category: Ivanti
-
Ivanti Endpoint Manager Mobile (EPMM) zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340)
CVE-2026-1281 is a critical remote code execution (RCE) vulnerability in Ivanti Endpoint Manager Mobile (EPMM). It stems from a code injection flaw in the product’s web services that allows an unauthenticated attacker to send crafted requests and execute arbitrary code on a vulnerable system without needing to log in. CVE-2026-1340 is also a critical code…