CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[Update] Multiple vulnerabilities in Ivanti Endpoint Manager Mobile (January 30, 2026)

unknownknown exploitedpublic exploitCVE-2026-1340CVE-2026-1281
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
[Update on February 9, 2026] On February 6, 2026, Ivanti made RPM detection scripts for indicators of compromise available, to be used depending on the installed version of EPMM. The vendor also updated its analysis guide (see Documentation section). [Update on February 2...

CSIRTS triage

What
Multiple vulnerabilities have been identified in Ivanti Endpoint Manager Mobile.
Who is affected
Users of Ivanti EPMM are affected.
Urgency
Remediation is important as vulnerabilities are actively exploited.
Action
Follow the vendor's guidance for RPM detection scripts and updates.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch EPMM

Get an email when a new EPMM advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-FR Alertes de sécurité (FR · national-cert · site)
Severity
unknown
Published
2026-01-30
Exploitation
Observed in the wild (CISA KEV)
Language
Machine-translated to English — verify against the original

Original advisory: https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-001/

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-1340coverage & exploitation statusNVD · CVE.org
CVE-2026-1281coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CERT-FR Alertes de sécurité