Two Ivanti EPMM zero-days exploited in attacks
Ivanti has disclosed two remote code execution vulnerabilities, CVE-2026-1281 and CVE-2026-1340, in Endpoint Manager Mobile (EPMM). Both have been exploited in zero-day attacks. A patch is expected later in the first quarter of 2026, but Ivanti has already released RPM scripts that can mitigate the flaws in affected versions. All EPMM versions are considered affected except 12.x.1.x RPM and 12.x.0.x RPM.
What this means for your organisation
EPMM manages mobile devices, and a system that manages devices holds high privileges over them by design. If it is compromised, an attacker can reach the mobile estate of the entire organisation, management included. With a fix weeks away, you have to run on mitigations and monitoring in the meantime, and that is a decision leadership should take deliberately.
Berigo recommends
- Check which EPMM version you run and apply Ivanti's RPM scripts immediately if you are affected.
- Limit internet exposure to what is strictly necessary until the patch is available.
- Review EPMM administrator accounts and logs for unexpected changes or logins.
- Agree with leadership what level of risk you accept while waiting, and document that decision.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch