CVE-2026-1340: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-04-08. EPSS: 98.6% chance of exploitation in the next 30 days.
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Affected products
- Ivanti Endpoint Manager Mobile: up to and including 12.7.0.0
Published 2026-01-29. Last modified 2026-06-17.