LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-1281: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 29, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 1, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-1281 to its Known Exploited Vulnerabilities catalog on Jan 29, 2026, with a federal patch deadline of Feb 1, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that permits unauthenticated remote code execution. The flaw affects organizations that rely on this product for mobile device and endpoint management, where successful exploitation can grant attackers direct control over the server without prior authentication.

How it works

CWE-94 describes improper control over code generation, allowing an attacker to supply input that the application later executes as code. In this case the vulnerability class enables an unauthenticated remote actor to inject and run arbitrary commands on the EPMM server. The product accepts untrusted data in a context where it is subsequently interpreted or compiled, bypassing normal input validation and sandboxing mechanisms typical of management platforms.

Am I affected? How to find it in your systems

EPMM is typically deployed as an on-premises or cloud-hosted mobile device management server that communicates with endpoints and integrates with directory services. Inventory all instances by checking installed packages, container images, or cloud service listings that reference Ivanti Endpoint Manager Mobile. Confirm the exact versions and configurations present against the vendor advisory, because only the advisory lists the affected builds. Review web server and application logs for anomalous unauthenticated requests that result in process creation or unexpected script execution; correlate these events with outbound connections or file writes on the management host.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation. After patching, review and tighten any custom scripts or extensions that accept external input, enforce strict input sanitization for all management interfaces, and disable unnecessary remote management features. Re-test integrations with directory services and endpoint agents to ensure they do not reintroduce code paths that accept untrusted data.

If you can't patch immediately

If your data may have been exposed

Actively exploited instances of this vulnerability class have led to unauthorized access and subsequent data exposure. Organizations can run a free exposure scan of their corporate email domains against known breach data sets to determine whether credentials or other identifiers have already appeared in public repositories.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Endpoint Manager Mobile (EPMM)
WeaknessCWE-94
Added to CISA KEVJan 29, 2026
Federal patch deadlineFeb 1, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities