HomeIntelligenceBrief
🛡️ VULNERABILITY BRIEF🔴 Critical🛡️ Vulnerability

Critical Unauthenticated RCE in Ivanti Endpoint Manager Mobile (CVE-2026-1340) Added to CISA KEV Catalog

A critical code‑injection flaw (CVE‑2026‑1340) in Ivanti Endpoint Manager Mobile allows unauthenticated remote code execution. The vulnerability is actively exploited and has been placed in CISA’s Known Exploited Vulnerabilities catalog, prompting an urgent patch deadline for federal agencies and a strong recommendation for private organizations.

🛡️ LiveThreat™ Intelligence · 📅 April 09, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
🛡️
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
5 recommended
📰
Source
securityaffairs.com

Critical Unauthenticated RCE in Ivanti Endpoint Manager Mobile (CVE-2026-1340) Added to CISA KEV Catalog

What It Is — A critical code‑injection flaw in Ivanti Endpoint Manager Mobile (EPMM) that enables unauthenticated remote code execution. CVSS 9.8.

Exploitability — Actively exploited in the wild; a proof‑of‑concept was released shortly after disclosure. The vulnerability is now listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog.

Affected Products — Ivanti Endpoint Manager Mobile versions 12.5.0.0 and earlier, 12.5.1.0 and earlier, 12.6.0.0 and earlier, 12.6.1.0 and earlier, 12.7.0.0 and earlier (RPM 12.x series).

TPRM Impact — Organizations that rely on Ivanti EPMM for device management face a supply‑chain risk: a compromised manager can execute arbitrary code on managed endpoints, potentially exposing corporate data and disrupting operations.

Recommended Actions

  • Apply Ivanti’s patch (12.6.0.0+, 12.6.1.0+, 12.7.0.0+).
  • Deploy the Ivanti Exploitation Detection RPM and review generated logs.
  • Conduct a forensic review of any pre‑patch alerts.
  • Update internal asset inventories to reflect the patched version.
  • For federal agencies, meet the CISA remediation deadline of 11 April 2026.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/190519/security/u-s-cisa-adds-a-flaw-in-ivanti-epmm-to-its-known-exploited-vulnerabilities-catalog-2.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

🛡️

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.