#ivanti-epmm

[ follow ]
#cve-2026-1281
EU data protection
fromThe Hacker News
1 week ago

Dutch Authorities Confirm Ivanti Zero-Day Exploit Exposed Employee Contact Data

Cyberattacks exploiting Ivanti EPMM flaws accessed employee names, business emails, and phone numbers at Dutch agencies, the European Commission, and Finland's Valtori.
fromTheregister
2 weeks ago

Ivanti's January bad luck continues as 0-days hit customers

Tracked as CVE-2026-1281 and CVE-2026-1340, both bugs affect Ivanti Endpoint Manager Mobile (EPMM). They're also both rated a near-maximum CVSS score of 9.8 and allow for unauthenticated remote code execution (RCE) - about as bad as it gets. The security shop said in its advisory: "We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure.
Information security
fromSecurityWeek
2 weeks ago

Ivanti Patches Exploited EPMM Zero-Days

Ivanti on Thursday announced emergency patches for two critical-severity vulnerabilities in Endpoint Manager Mobile (EPMM) that have been exploited in the wild as zero-days. Tracked as CVE-2026-1281 and CVE-2026-1340 (CVSS score of 9.8), the bugs are described as code injection issues that could be exploited by unauthenticated attackers to achieve remote code execution (RCE). The flaws impact the in-house application distribution and the Android file transfer configuration features of EPMM.
Information security
Information security
fromTheregister
5 months ago

CISA: Attacker exploited Ivanti bugs, dropped snoopy malware

Two zero-day Ivanti EPMM vulnerabilities (CVE-2025-4427, CVE-2025-4428) were chained to deploy malware and enable arbitrary code execution on compromised servers.
#cve-2025-4427
Information security
fromThe Hacker News
8 months ago

Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks

Ivanti Endpoint Manager Mobile vulnerabilities exploited by a China-based group pose significant risks across multiple sectors worldwide.
[ Load more ]