CVE-2026-1281: 
Ivanti Endpoint Manager Mobile vulnerability analysis and mitigation

Overview

CVE-2026-1281 is a critical code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthenticated attackers to achieve remote code execution (RCE) over the network without any user interaction. The vulnerability affects EPMM versions 12.5.0.0 and earlier, as well as versions 12.5.1.0, 12.6.0.0, 12.6.1.0, and 12.7.0.0. It was publicly disclosed on January 29, 2026, with Ivanti releasing security updates on January 30, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (Ivanti Advisory, CISA KEV).

Technical details

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection) and stems from insufficient input validation in Ivanti EPMM's handling of user-supplied data, allowing attackers to inject and execute arbitrary code server-side. Exploitation requires no authentication, no privileges, and no user interaction — attackers can send a specially crafted network request directly to the exposed EPMM service. Technical analysis by watchTowr Labs revealed the vulnerability involves exploitation of bash arithmetic expansion, a novel technique enabling pre-authentication RCE (watchTowr Labs). Multiple public proof-of-concept exploits are available on GitHub, and a Metasploit module was also developed (Rapid7).

Impact

Successful exploitation grants attackers complete control over the affected EPMM server, with high confidentiality, integrity, and availability impacts. Because EPMM is a Mobile Device Management (MDM) platform, compromise can expose sensitive employee contact data, device credentials, location data, and mobile infrastructure configurations for all managed devices. Documented real-world breaches include the European Commission's mobile management infrastructure and the Dutch Data Protection Authority, with exploitation confirmed across nearly 100 organizations including government agencies and enterprises globally (BleepingComputer, Cybersecurity Dive). Post-exploitation activity has included deployment of dormant backdoors ("sleeper webshells") designed to persist through patching (Help Net Security).

Exploitability

CVE-2026-1281 was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on January 29, 2026, with a federal remediation deadline of February 1, 2026, confirming active in-the-wild exploitation as a zero-day (CISA KEV). Multiple public PoC exploits exist on GitHub (e.g., Ashwesker/Ashwesker-CVE-2026-1281, MehdiLeDeaut/CVE-2026-1281-Ivanti-EPMM-RCE), and a Metasploit module was merged in February 2026. The EPSS score is approximately 0.164 (16.4%). Threat intelligence indicates that 83% of exploitation attempts were traced to a single IP address associated with bulletproof hosting infrastructure (Prospero), suggesting a concentrated, organized threat actor (The Hacker News). The Nezha malware family has been observed weaponizing this vulnerability, and MuddyWater (an Iranian APT) has been linked to related exploitation activity (Feedly Intelligence).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Ivanti EPMM instances using tools like Shodan or Censys, targeting versions 12.7.0.0, 12.6.1.0, 12.6.0.0, 12.5.1.0, or 12.5.0.0 and earlier. Approximately 850 EPMM servers were identified as internet-exposed at the time of disclosure.
  2. Identify vulnerable endpoint: Locate the EPMM API or web-facing endpoint susceptible to code injection. The vulnerability involves improper handling of user-controlled input passed to a bash context, enabling arithmetic expansion abuse.
  3. Craft malicious payload: Construct an unauthenticated HTTP request containing a code injection payload exploiting bash arithmetic expansion (e.g., using $((...)) or similar constructs) in a vulnerable parameter processed by the EPMM server.
  4. Send exploit request: Deliver the crafted request to the target EPMM server without any authentication. The server processes the malicious input and executes attacker-controlled code as the EPMM service account.
  5. Achieve RCE and establish persistence: Execute arbitrary commands on the server — common post-exploitation actions observed include deploying dormant web shells ("sleeper shells" such as 403.jsp) designed to survive patching, exfiltrating credentials and MDM data, and establishing reverse shells for persistent access (watchTowr Labs, Rapid7).

Indicators of compromise

  • Network: Unusual or unexpected HTTP/HTTPS requests to EPMM API endpoints from unknown external IPs; outbound connections from the EPMM server to unknown external hosts; exploitation traffic originating from bulletproof hosting IPs (notably Prospero ASN infrastructure); scanning activity targeting EPMM login or API paths.
  • File System: Presence of unexpected JSP web shells in the EPMM web application directory, particularly files named 403.jsp or similarly obfuscated names ("sleeper shells"); new or modified files in EPMM installation directories with recent timestamps inconsistent with legitimate updates.
  • Logs: EPMM access logs showing unauthenticated requests with anomalous parameter values containing bash arithmetic expressions or shell metacharacters; error logs indicating unexpected code execution or process spawning; authentication logs showing access using credentials that may have been harvested from the EPMM database.
  • Process: Unexpected child processes spawned by the EPMM Java or service process (e.g., bash, sh, curl, wget, python); unusual cron jobs or scheduled tasks created under the EPMM service account.
  • Threat Intelligence: IP addresses associated with the Prospero bulletproof hosting provider observed in connection logs; indicators associated with the Nezha malware family on EPMM hosts (watchTowr Labs, Telekom Security).

Mitigation and workarounds

Ivanti released security updates on January 30, 2026; organizations should apply the RPM patches for their respective EPMM versions (12.x.0.x RPM or 12.x.1.x RPM) immediately (Ivanti Advisory). CISA mandated federal agencies patch by February 1, 2026 under BOD 22-01. If immediate patching is not possible, restrict or disable network access to EPMM systems from the internet, and review logs for signs of compromise dating back to the system's initial exposure. Organizations should also inventory all affected versions, review EPMM for dormant web shells or unauthorized files, and rotate any credentials stored or managed by the EPMM platform, as stolen credentials were later used in follow-on attacks (CVE-2026-6973) (CISA KEV, BleepingComputer).

Community reactions

Ivanti's disclosure was met with significant concern from the security community given the product's role in managing enterprise mobile devices and the immediate confirmation of zero-day exploitation. watchTowr Labs published a detailed technical write-up praising the novelty of the bash arithmetic expansion technique, which garnered wide attention on Reddit's r/netsec and r/blueteamsec communities. Rapid7, Tenable, Horizon3.ai, and Unit 42 (Palo Alto Networks) all published emergency threat reports within 24–48 hours of disclosure. The European Commission's subsequent breach disclosure and the Dutch Data Protection Authority's self-reported compromise amplified media coverage significantly, with The Register, BleepingComputer, and CyberScoop covering the geopolitical dimensions. GreyNoise reported a massive spike in exploitation attempts, and the finding that 83% of attacks originated from a single IP on bulletproof hosting infrastructure drew widespread commentary on the organized nature of the campaign (BleepingComputer, The Hacker News).

Additional resources


Source: This report was generated using AI

Related Ivanti Endpoint Manager Mobile vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5788CRITICAL9.8
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-7821CRITICAL9.1
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-5787CRITICAL9.1
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-18851HIGH8.8
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesSep 08, 2026
CVE-2026-6973HIGH7.2
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
YesYesMay 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management