Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)
Reported exploitedIvanti Endpoint Manager Mobile (EPMM) Read at watchTowr Labs
Below is the opening; the full story is at watchTowr Labs.
From watchTowr Labs
When Ivanti removed the embargoes from CVE-2026-1281 and CVE-2026-1340 - actively exploited pre-auth Remote Command Execution vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) solution - we sighed with relief.
Clearly, the universe had decided to continue mocking Secure-By-Design signers right on schedule - every January.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.