CVE-2026-1340: 
Ivanti Endpoint Manager Mobile vulnerability analysis and mitigation

Overview

CVE-2026-1340 is a code injection vulnerability (CWE-94) in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthenticated remote attackers to execute arbitrary code on affected servers. It affects EPMM versions up to and including 12.7.0.0 and was publicly disclosed on January 29, 2026. The vulnerability was exploited as a zero-day before patches were available, with Ivanti releasing security updates on February 20, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (Ivanti Advisory, CISA KEV).

Technical details

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection) and is exploitable over the network with no authentication, no user interaction, and low attack complexity. Technical analysis by watchTowr Labs revealed that the exploitation mechanism leverages Bash arithmetic expansion — an unusual and sophisticated technique — to achieve pre-authentication remote code execution on the EPMM server (watchTowr Labs). CVE-2026-1340 is typically chained with a companion vulnerability, CVE-2026-1281 (an authentication bypass), to form a complete unauthenticated RCE exploit chain (Rapid7 ETR, Tenable). Public PoC code and Metasploit modules were subsequently released, lowering the barrier for exploitation (Rapid7 Metasploit).

Impact

Successful exploitation grants attackers unauthenticated remote code execution on the EPMM server, resulting in complete compromise of confidentiality, integrity, and availability. Because EPMM is a Mobile Device Management (MDM) platform, a compromised server can be weaponized to push malicious configurations to all enrolled mobile devices across an organization, dramatically amplifying the blast radius. Attackers have been observed deploying dormant backdoors (including "sleeper" web shells such as 403.jsp) and the Nezha malware to maintain persistent, stealthy access even after patching (watchTowr, WithSecure). High-profile victims include the Dutch government and the European Commission, where employee contact data was exposed (BleepingComputer).

Exploitability

CVE-2026-1340 was actively exploited as a zero-day at the time of disclosure and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog with a due date of April 11, 2026 (CISA KEV). Public PoC code and a Metasploit module were released in February 2026, and exploit code is available on GitHub and Sploitus (Rapid7 Metasploit). Threat intelligence indicates that approximately 83% of exploitation attempts were traced to a single IP address associated with the bulletproof hosting provider Prospero, suggesting a concentrated, organized threat actor (BleepingComputer). The EPSS score is approximately 0.00184, though real-world exploitation activity far exceeds what this score suggests given confirmed in-the-wild attacks. Exploitation has been linked to the Nezha malware family and attributed to actors targeting government and enterprise networks across Europe (Unit 42).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Ivanti EPMM servers (versions ≤ 12.7.0.0) using tools like Shodan or Censys. Approximately 850 EPMM servers were found exposed on the internet at the time of disclosure.
  2. Authentication Bypass (CVE-2026-1281): Send a crafted HTTP request to the EPMM API endpoint to exploit the companion authentication bypass vulnerability, obtaining access to authenticated API functionality without valid credentials.
  3. Code Injection via Bash Arithmetic Expansion (CVE-2026-1340): Submit a malicious payload to a vulnerable EPMM endpoint that leverages Bash arithmetic expansion to inject and execute arbitrary shell commands on the server. The injection occurs through improper handling of user-controlled input that is passed to a shell context.
  4. Establish Persistence: Deploy a dormant web shell (e.g., 403.jsp) or the Nezha malware implant to maintain persistent access. Attackers have been observed placing backdoors that survive patching cycles.
  5. Lateral Movement / Data Exfiltration: Use the compromised EPMM server's privileged position to access enrolled device data (credentials, location data, contact information), push malicious MDM profiles to managed devices, or pivot into the broader enterprise network (watchTowr Labs, Unit 42, WithSecure).

Indicators of compromise

  • Network: Unusual HTTP requests to EPMM API endpoints from unexpected source IPs, particularly from IP ranges associated with the Prospero bulletproof hosting provider; outbound connections from the EPMM server to unknown external IPs; exploitation traffic originating from a single IP responsible for ~83% of attacks.
  • File System: Presence of unexpected JSP web shells (e.g., 403.jsp) in the EPMM web application directories; new or modified files in EPMM installation paths with recent timestamps inconsistent with normal operations; Nezha malware binaries or related implant artifacts.
  • Logs: EPMM access logs showing unauthenticated requests to authenticated API endpoints; anomalous API calls with malformed or encoded parameters containing Bash arithmetic expressions (e.g., $((...))); log entries showing command execution or shell spawning from the EPMM process.
  • Process: Unexpected child processes spawned by the EPMM Java or application server process (e.g., /bin/bash, curl, wget, python); unusual cron jobs or scheduled tasks created under the EPMM service account.
  • Enrolled Devices: Unauthorized MDM configuration profiles pushed to managed devices; unexpected changes to device enrollment or policy settings (watchTowr, WithSecure, Unit 42).

Mitigation and workarounds

Ivanti released security patches on February 20, 2026, covering EPMM 12.x versions (both 12.x.0.x and 12.x.1.x RPM packages). Organizations should apply the patches documented in the Ivanti security advisory immediately (Ivanti Advisory). CISA mandated that federal agencies patch by April 11, 2026, and recommends all organizations follow Ivanti's guidelines to assess exposure and check for signs of compromise on all internet-accessible EPMM instances (CISA KEV). As interim measures, restrict network access to EPMM servers to authorized administrators only, implement network segmentation to isolate EPMM infrastructure, and monitor EPMM logs for suspicious activity. Organizations should also verify the integrity of EPMM configurations and enrolled device profiles for signs of unauthorized modifications or backdoor installations, as dormant web shells may persist even after patching.

Community reactions

Ivanti issued a security advisory and analysis guidance shortly after disclosure, acknowledging active exploitation affecting a limited number of customers (Ivanti Advisory). watchTowr Labs published a widely-cited technical write-up praising the sophistication of the Bash arithmetic expansion technique used in the exploit, generating significant discussion in the security community (watchTowr Labs). The European Commission's disclosure of a breach linked to these vulnerabilities, along with the Dutch government's confirmation of compromise, drew substantial media coverage and regulatory attention (BleepingComputer). CERT-EU, CISA, and multiple national CERTs (Belgium, Luxembourg, Singapore, Ireland, Austria) issued advisories urging immediate patching. The NCSC UK CTO summary and Risky Biz newsletter both highlighted the incident as a significant supply-chain risk for government MDM infrastructure.

Additional resources


Source: This report was generated using AI

Related Ivanti Endpoint Manager Mobile vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5788CRITICAL9.8
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-7821CRITICAL9.1
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-5787CRITICAL9.1
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-18851HIGH8.8
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesSep 08, 2026
CVE-2026-6973HIGH7.2
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
YesYesMay 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management