Skip to content

CISA Adds Ivanti EPMM CVE-2026-1340 to KEV — Federal Patch Deadline Today

CISA has added CVE-2026-1340, a critical unauthenticated remote code execution flaw in Ivanti Endpoint Manager Mobile, to the Known Exploited Vulnerabilities catalogue with a federal agency deadline of 11 April. The vulnerability chains with CVE-2026-1281 to enable full appliance takeover and has been actively exploited since January 2026. All organisations running Ivanti EPMM on-premises must patch immediately.

Article network-security

The Vulnerability Chain

Ivanti Endpoint Manager Mobile (EPMM) — the enterprise mobile device management platform formerly known as MobileIron Core — is affected by two critical unauthenticated remote code execution vulnerabilities that have been actively exploited as zero-days since January 2026.

CVE-2026-1281 (CVSS 9.8): A code injection flaw in legacy bash scripts used by EPMM’s Apache web server to handle URL rewriting. Attackers can send crafted HTTP requests that trigger arbitrary command execution without any authentication.

CVE-2026-1340 (CVSS 9.8): A code injection vulnerability in EPMM’s Android File Transfer mechanism. Like CVE-2026-1281, exploitation requires no credentials and no user interaction. CISA added CVE-2026-1340 to the Known Exploited Vulnerabilities catalogue on 8 April 2026, giving all US Federal Civilian Executive Branch agencies until 11 April to apply patches — a four-day emergency window reflecting the severity of active exploitation.

The two vulnerabilities are frequently chained: CVE-2026-1281 provides the initial foothold and CVE-2026-1340 extends attacker capability on the compromised appliance.

Exploitation Activity

Unit 42 researchers documented widespread and largely automated exploitation activity against both vulnerabilities beginning shortly after Ivanti disclosed them in January 2026. The attack pattern is consistent:

  1. Unauthenticated attacker sends a crafted HTTP request to the EPMM web interface
  2. Code injection achieves execution on the EPMM appliance under the Apache service account
  3. Second-stage payload is downloaded — typically a web shell, cryptominer, or persistent backdoor
  4. Attacker establishes persistent access and conducts lateral movement or data collection

Because EPMM is a mobile device management platform, a compromised appliance provides access to:

  • Full device inventory, configuration profiles, and enrolled device certificates
  • Push notification infrastructure that can be abused to issue commands to managed devices
  • Network credentials and VPN configurations distributed to mobile devices
  • Potentially sensitive data synchronised through the MDM platform

Why MDM Platforms Are High-Value Targets

Ivanti EPMM is deployed by thousands of enterprises, government agencies, and educational institutions worldwide to manage smartphones, tablets, and laptops. A compromise of the MDM appliance is equivalent to compromising the management plane for an organisation’s entire mobile fleet — an attacker who controls EPMM can see every device, its configuration, and in many implementations push malicious profiles or certificates to enrolled devices.

This is not Ivanti’s first significant EPMM vulnerability under active exploitation. The platform was also targeted via CVE-2023-35078 and CVE-2023-35082 in 2023, demonstrating sustained attacker interest in MDM infrastructure as a high-value pivot point.

Affected Versions and Patching

Both vulnerabilities affect all supported on-premises EPMM major version lines through 12.7.x. Ivanti has released patch RPMs for all supported branches. A permanent fix is included in version 12.8.0.0.

Patching is straightforward and requires no downtime per Ivanti’s advisory — the fix can be applied as a live update without service interruption, removing any operational justification for delay.

Immediate (today):

  1. Identify all EPMM instances in your environment — including those managed by third-party IT providers or hosted at branch offices
  2. Apply the patch appropriate for your version branch; verify the installed RPM version matches Ivanti’s advisory post-patch
  3. Restrict EPMM admin interface access to management networks only — remove any direct internet exposure of the admin panel if it exists
  4. Review EPMM logs for the past 90 days for unusual HTTP requests, unexpected outbound connections, and anomalous device command issuance

Detection:

  • Alert on unexpected processes spawned by the Apache service account on EPMM
  • Monitor for web shell indicators: unusual files in web-accessible directories, HTTP POST requests returning command output
  • Review device configuration push history for any profiles or certificates issued outside of normal change management

If you believe you are already compromised:

Treat the EPMM appliance as fully compromised. Isolate it from the network, preserve forensic images for incident analysis, and begin rotating all credentials and certificates that have been distributed through the platform. Engage your incident response team immediately — the combination of device management access and credential visibility makes this a potentially severe breach scenario.

Share this article

Related Intelligence

🌐 Network

Ivanti Sentry CVE-2026-10523 (CVSS 9.9): Second Critical Flaw Chains with CVE-2026-10520 for Complete Device Takeover

Ivanti has disclosed a second critical vulnerability in Sentry — CVE-2026-10523, an authentication bypass scoring CVSS 9.9 — that chains with the previously patched CVE-2026-10520 (CVSS 10.0) to enable complete unauthenticated takeover of the MDM gateway. Organisations that deployed the initial patch must apply additional updates; the two CVEs affect overlapping but distinct code paths.

#ivanti +7
🌐 Network

PAN-OS CVE-2026-0300 — Unauthenticated RCE Zero-Day Actively Exploited in Firewall Espionage Attacks

A critical unauthenticated remote code execution vulnerability in Palo Alto Networks PAN-OS has been under active exploitation since at least early April 2026, linked to espionage-motivated threat actors targeting government and critical infrastructure networks. CVE-2026-0300 affects the User-ID authentication portal on VM-Series and hardware firewalls; CISA added it to the KEV catalogue on 6 May 2026. Patches are available — apply immediately.

#palo-alto +9
🌐 Network

Public Exploit Released for Critical FortiSandbox RCE (CVE-2026-39808, CVSS 9.1) — Unauthenticated Root Access

A public proof-of-concept exploit has been released for CVE-2026-39808, a critical OS command injection vulnerability in Fortinet FortiSandbox that allows unauthenticated attackers to execute arbitrary commands as root via a single HTTP request. A companion authentication bypass flaw (CVE-2026-39813) affects the same versions. Patch to FortiSandbox 4.4.9 or 5.0.6 immediately.

#fortinet +8