CRITICAL

CVE-2026-1340

Ivanti Endpoint Manager Mobile 2026-01-29 CVSS v3.1
CVSS
9.8
KEV

Description

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Summary dbcve.org

A code injection vulnerability in Ivanti Endpoint Manager Mobile enables unauthenticated attackers to execute arbitrary code remotely without any credentials, leading to complete system compromise.

Mitigation

Apply vendor-supplied patches immediately upon release; meanwhile, restrict network exposure of the EPMM management interface and implement detection rules for anomalous activity.

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

98.68%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE