CRITICAL
CVE-2026-1340
CVSS
9.8
KEV
Description
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Summary dbcve.org
A code injection vulnerability in Ivanti Endpoint Manager Mobile enables unauthenticated attackers to execute arbitrary code remotely without any credentials, leading to complete system compromise.
Mitigation
Apply vendor-supplied patches immediately upon release; meanwhile, restrict network exposure of the EPMM management interface and implement detection rules for anomalous activity.
Weakness (CWE)
CWE-94
Code Injection
EPSS Score
98.68%
Probability of exploitation in next 30 days
99.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.