CVE-2026-1281
9.8 CISA KEVIvanti · Endpoint Manager Mobile (EPMM)
A code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) allows unauthenticated remote attackers to execute arbitrary code via crafted HTTP requests.
Executive summary
This critical code injection vulnerability in Ivanti Endpoint Manager Mobile is currently being exploited in the wild and enables unauthenticated remote code execution.
Vulnerability
This is a code injection flaw (CWE-94) that allows unauthenticated remote attackers to achieve remote code execution by sending specially crafted HTTP requests to the target system. The vulnerability does not require any user interaction or authentication to trigger.
Business impact
The CVSS score of 9.8 reflects the extreme severity of this flaw, as it allows full system compromise without any authentication. Successful exploitation grants attackers total control over the affected EPMM instance, potentially leading to the theft of sensitive mobile device data, credential harvesting, or the lateral movement of threats into the internal corporate network. The active exploitation status significantly increases the operational risk to any organization running vulnerable versions of this software.
Remediation
Immediate Action: Apply the appropriate RPM update (12.x.0.x or 12.x.1.x) immediately as provided by the vendor; a permanent fix is integrated into release version 12.8.0.0.
Proactive Monitoring: Review web server access logs for anomalous HTTP requests, particularly those containing suspicious code patterns or unexpected headers, and monitor for unauthorized process execution on the EPMM appliance.
Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to filter or block malicious HTTP requests targeting the vulnerable endpoints until patching is complete.
Exploitation status
Public Exploit Available: Yes, a Metasploit module exists and multiple public proof-of-concept repositories are available on GitHub.
Analyst recommendation
Due to the confirmed active exploitation and the critical severity of this vulnerability, organizations must treat this as a top-priority security event. Administrators should apply the vendor-provided RPM updates immediately to eliminate the remote code execution vector. If patching cannot occur instantly, ensure the appliance is isolated from the public internet until the necessary updates are deployed to prevent unauthorized access.