CRITICAL

CVE-2026-1281

Ivanti Endpoint Manager Mobile 2026-01-29 CVSS v3.1
CVSS
9.8
KEV

Description

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Summary dbcve.org

Code injection vulnerability in Ivanti Endpoint Manager Mobile that allows attackers to execute arbitrary code remotely without any authentication credentials.

Mitigation

Apply vendor-supplied patches immediately; until available, restrict network exposure of the affected service to trusted networks only.

Patch Commit

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

98.58%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE