CRITICAL
CVE-2026-1281
CVSS
9.8
KEV
Description
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Summary dbcve.org
Code injection vulnerability in Ivanti Endpoint Manager Mobile that allows attackers to execute arbitrary code remotely without any authentication credentials.
Mitigation
Apply vendor-supplied patches immediately; until available, restrict network exposure of the affected service to trusted networks only.
Weakness (CWE)
CWE-94
Code Injection
EPSS Score
98.58%
Probability of exploitation in next 30 days
99.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.