🔴 CVE-2026-1281

Critical code injection vulnerability in Ivanti Endpoint Manager Mobile allowing unauthenticated remote code execution. This vulnerability is actively exploited in zero-day attacks and listed on CISA's KEV catalog.

← Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-01-29

Added to CISA KEV: 2026-01-29 0 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-01-29)

CVE-2026-1281 is a code injection vulnerability affecting Ivanti Endpoint Manager Mobile (EPMM). This vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog on January 29, 2026 [1][5].

Here's a breakdown of what is known about its exploitation:

  • Internet-facing applications or services: While not explicitly stated that EPMM is exclusively internet-facing, vulnerabilities in Mobile Device Management (MDM) products often have implications for systems that manage mobile devices within an enterprise, which can include internet-facing components. The nature of code injection vulnerabilities can allow for remote execution, suggesting potential exposure if the EPMM service is accessible.
  • Evidence of active exploitation in the wild: Yes, CVE-2026-1281 has been exploited in zero-day attacks [2][4]. Ivanti disclosed these vulnerabilities after they were exploited [2].
  • Attack vectors and exploitation methods: The vulnerability is a code injection flaw that could allow unauthenticated remote attackers to execute arbitrary code on vulnerable devices [1][2]. This means an attacker does not need to log in or have any prior credentials to exploit this vulnerability.
  • Use in targeted attacks: The information indicates that these vulnerabilities were exploited in zero-day attacks [2][4], which often implies targeted campaigns rather than widespread, opportunistic attacks.
  • CISA Known Exploited Vulnerabilities status: CVE-2026-1281 is listed on CISA's Known Exploited Vulnerabilities (KEV) Catalog [1][5]. This designation means CISA has confirmed evidence of active exploitation and requires U.S. federal agencies to apply available security patches or mitigations by a specific deadline.
  • Technical details about internet exploitability: The vulnerability allows for unauthenticated remote code execution [1][2]. This implies that if the Ivanti EPMM service is accessible over a network (including the internet), an attacker could potentially exploit it remotely without needing any prior authentication. The CVSS score for this vulnerability is 9.8 (Critical) [3].

Sources

  1. CVE-2026-1281 - Exploits & Severity - Feedly

    CVE-2026-1281 Release: 2026-01-29 Due Date: 2026-02-01 Vendor: Ivanti Product: Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. CISA added CVE-2026-1281 to the lis…

  2. Ivanti warns of two EPMM flaws exploited in zero-day attacks

    Ivanti has disclosed two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1281 and CVE-2026-1340, that were exploited in zero-day attacks.

  3. CVE-2026-1281 - Ivanti Endpoint Manager Mobile Code Injection Vulnerability

    The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE. Score Version Severity Vector Exploitability Score Impact Score Source 9.8 CVSS 3.1 CRITIC…

  4. CISA KEV Alert: Patch CVE-2026-1281 in Ivanti EPMM Now

    CISA’s Known Exploited Vulnerabilities (KEV) Catalog has one more entry to worry about: on January 29, 2026 the agency added CVE-2026-1281, a code-injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM). The short version: this is a classic, high-risk attack vector in a mobile device manage…

  5. Known Exploited Vulnerabilities Catalog - CISA

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catal…