
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1281 is a critical code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthenticated attackers to achieve remote code execution (RCE) over the network without any user interaction. The vulnerability affects EPMM versions 12.5.0.0 and earlier, as well as versions 12.5.1.0, 12.6.0.0, 12.6.1.0, and 12.7.0.0. It was publicly disclosed on January 29, 2026, with Ivanti releasing security updates on January 30, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (Ivanti Advisory, CISA KEV).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection) and stems from insufficient input validation in Ivanti EPMM's handling of user-supplied data, allowing attackers to inject and execute arbitrary code server-side. Exploitation requires no authentication, no privileges, and no user interaction — attackers can send a specially crafted network request directly to the exposed EPMM service. Technical analysis by watchTowr Labs revealed the vulnerability involves exploitation of bash arithmetic expansion, a novel technique enabling pre-authentication RCE (watchTowr Labs). Multiple public proof-of-concept exploits are available on GitHub, and a Metasploit module was also developed (Rapid7).
Successful exploitation grants attackers complete control over the affected EPMM server, with high confidentiality, integrity, and availability impacts. Because EPMM is a Mobile Device Management (MDM) platform, compromise can expose sensitive employee contact data, device credentials, location data, and mobile infrastructure configurations for all managed devices. Documented real-world breaches include the European Commission's mobile management infrastructure and the Dutch Data Protection Authority, with exploitation confirmed across nearly 100 organizations including government agencies and enterprises globally (BleepingComputer, Cybersecurity Dive). Post-exploitation activity has included deployment of dormant backdoors ("sleeper webshells") designed to persist through patching (Help Net Security).
CVE-2026-1281 was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on January 29, 2026, with a federal remediation deadline of February 1, 2026, confirming active in-the-wild exploitation as a zero-day (CISA KEV). Multiple public PoC exploits exist on GitHub (e.g., Ashwesker/Ashwesker-CVE-2026-1281, MehdiLeDeaut/CVE-2026-1281-Ivanti-EPMM-RCE), and a Metasploit module was merged in February 2026. The EPSS score is approximately 0.164 (16.4%). Threat intelligence indicates that 83% of exploitation attempts were traced to a single IP address associated with bulletproof hosting infrastructure (Prospero), suggesting a concentrated, organized threat actor (The Hacker News). The Nezha malware family has been observed weaponizing this vulnerability, and MuddyWater (an Iranian APT) has been linked to related exploitation activity (Feedly Intelligence).
$((...)) or similar constructs) in a vulnerable parameter processed by the EPMM server.403.jsp) designed to survive patching, exfiltrating credentials and MDM data, and establishing reverse shells for persistent access (watchTowr Labs, Rapid7).403.jsp or similarly obfuscated names ("sleeper shells"); new or modified files in EPMM installation directories with recent timestamps inconsistent with legitimate updates.bash, sh, curl, wget, python); unusual cron jobs or scheduled tasks created under the EPMM service account.Ivanti released security updates on January 30, 2026; organizations should apply the RPM patches for their respective EPMM versions (12.x.0.x RPM or 12.x.1.x RPM) immediately (Ivanti Advisory). CISA mandated federal agencies patch by February 1, 2026 under BOD 22-01. If immediate patching is not possible, restrict or disable network access to EPMM systems from the internet, and review logs for signs of compromise dating back to the system's initial exposure. Organizations should also inventory all affected versions, review EPMM for dormant web shells or unauthorized files, and rotate any credentials stored or managed by the EPMM platform, as stolen credentials were later used in follow-on attacks (CVE-2026-6973) (CISA KEV, BleepingComputer).
Ivanti's disclosure was met with significant concern from the security community given the product's role in managing enterprise mobile devices and the immediate confirmation of zero-day exploitation. watchTowr Labs published a detailed technical write-up praising the novelty of the bash arithmetic expansion technique, which garnered wide attention on Reddit's r/netsec and r/blueteamsec communities. Rapid7, Tenable, Horizon3.ai, and Unit 42 (Palo Alto Networks) all published emergency threat reports within 24–48 hours of disclosure. The European Commission's subsequent breach disclosure and the Dutch Data Protection Authority's self-reported compromise amplified media coverage significantly, with The Register, BleepingComputer, and CyberScoop covering the geopolitical dimensions. GreyNoise reported a massive spike in exploitation attempts, and the finding that 83% of attacks originated from a single IP on bulletproof hosting infrastructure drew widespread commentary on the organized nature of the campaign (BleepingComputer, The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."