
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1340 is a code injection vulnerability (CWE-94) in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthenticated remote attackers to execute arbitrary code on affected servers. It affects EPMM versions up to and including 12.7.0.0 and was publicly disclosed on January 29, 2026. The vulnerability was exploited as a zero-day before patches were available, with Ivanti releasing security updates on February 20, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (Ivanti Advisory, CISA KEV).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection) and is exploitable over the network with no authentication, no user interaction, and low attack complexity. Technical analysis by watchTowr Labs revealed that the exploitation mechanism leverages Bash arithmetic expansion — an unusual and sophisticated technique — to achieve pre-authentication remote code execution on the EPMM server (watchTowr Labs). CVE-2026-1340 is typically chained with a companion vulnerability, CVE-2026-1281 (an authentication bypass), to form a complete unauthenticated RCE exploit chain (Rapid7 ETR, Tenable). Public PoC code and Metasploit modules were subsequently released, lowering the barrier for exploitation (Rapid7 Metasploit).
Successful exploitation grants attackers unauthenticated remote code execution on the EPMM server, resulting in complete compromise of confidentiality, integrity, and availability. Because EPMM is a Mobile Device Management (MDM) platform, a compromised server can be weaponized to push malicious configurations to all enrolled mobile devices across an organization, dramatically amplifying the blast radius. Attackers have been observed deploying dormant backdoors (including "sleeper" web shells such as 403.jsp) and the Nezha malware to maintain persistent, stealthy access even after patching (watchTowr, WithSecure). High-profile victims include the Dutch government and the European Commission, where employee contact data was exposed (BleepingComputer).
CVE-2026-1340 was actively exploited as a zero-day at the time of disclosure and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog with a due date of April 11, 2026 (CISA KEV). Public PoC code and a Metasploit module were released in February 2026, and exploit code is available on GitHub and Sploitus (Rapid7 Metasploit). Threat intelligence indicates that approximately 83% of exploitation attempts were traced to a single IP address associated with the bulletproof hosting provider Prospero, suggesting a concentrated, organized threat actor (BleepingComputer). The EPSS score is approximately 0.00184, though real-world exploitation activity far exceeds what this score suggests given confirmed in-the-wild attacks. Exploitation has been linked to the Nezha malware family and attributed to actors targeting government and enterprise networks across Europe (Unit 42).
403.jsp) in the EPMM web application directories; new or modified files in EPMM installation paths with recent timestamps inconsistent with normal operations; Nezha malware binaries or related implant artifacts.$((...))); log entries showing command execution or shell spawning from the EPMM process./bin/bash, curl, wget, python); unusual cron jobs or scheduled tasks created under the EPMM service account.Ivanti released security patches on February 20, 2026, covering EPMM 12.x versions (both 12.x.0.x and 12.x.1.x RPM packages). Organizations should apply the patches documented in the Ivanti security advisory immediately (Ivanti Advisory). CISA mandated that federal agencies patch by April 11, 2026, and recommends all organizations follow Ivanti's guidelines to assess exposure and check for signs of compromise on all internet-accessible EPMM instances (CISA KEV). As interim measures, restrict network access to EPMM servers to authorized administrators only, implement network segmentation to isolate EPMM infrastructure, and monitor EPMM logs for suspicious activity. Organizations should also verify the integrity of EPMM configurations and enrolled device profiles for signs of unauthorized modifications or backdoor installations, as dormant web shells may persist even after patching.
Ivanti issued a security advisory and analysis guidance shortly after disclosure, acknowledging active exploitation affecting a limited number of customers (Ivanti Advisory). watchTowr Labs published a widely-cited technical write-up praising the sophistication of the Bash arithmetic expansion technique used in the exploit, generating significant discussion in the security community (watchTowr Labs). The European Commission's disclosure of a breach linked to these vulnerabilities, along with the Dutch government's confirmation of compromise, drew substantial media coverage and regulatory attention (BleepingComputer). CERT-EU, CISA, and multiple national CERTs (Belgium, Luxembourg, Singapore, Ireland, Austria) issued advisories urging immediate patching. The NCSC UK CTO summary and Risky Biz newsletter both highlighted the incident as a significant supply-chain risk for government MDM infrastructure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."