Skip to content

Ivanti Endpoint Manager Mobile (CVE-2026-1281)

CVE-2026-1281CWE-94OWASP A03:2021CVSS 9.8Updated October 1, 20263 min read

CVE-2026-1281 and its twin CVE-2026-1340 are code injection flaws in Ivanti Endpoint Manager Mobile (EPMM) that let an unauthenticated attacker run commands on the server with a single web request. Ivanti patched them on 29 January 2026, but the Dutch NCSC later found they had already been abused in August 2025. Patching does not remove an attacker who got in earlier.

Affected
EPMM 12.5.0.0, 12.6.0.0 and 12.7.0.0 and earlier, plus 12.5.1.0 and 12.6.1.0
Patched in
January 2026 RPM hotfix (12.x.0.x or 12.x.1.x); releases 12.6.1.1, 12.7.0.1 and 12.8.0.1
Actively exploited
yes

A mobile device management server knows a lot about every phone it manages: who carries it, its number, its IMEI and often where it is. In January 2026 it emerged that attackers could take over Ivanti’s on-premises MDM server without logging in. Dutch investigators later traced successful abuse back to August 2025.

What is CVE-2026-1281

Ivanti Endpoint Manager Mobile, formerly MobileIron Core, is the server organisations run themselves to manage phones and tablets. Because those devices must reach it from anywhere, it usually sits on the internet: BSI cites Shadowserver counting around 550 exposed appliances in Germany alone.

Two of its features, In-House Application Distribution and Android File Transfer Configuration, handed parts of a web address to old bash scripts. According to Unit 42, bash evaluated that input as an expression, so a crafted GET request made the server run the attacker’s commands. CVE-2026-1281 sits in the first feature, CVE-2026-1340 in the second; Ivanti scores both 9.8. That is remote code execution without an account.

What makes it serious is what the server holds. According to the NCSC, its MIFS database contains account data with encrypted and hashed passwords, Active Directory group memberships, Office 365 tokens, phone and IMEI numbers, and location data including home and work locations.

What the attackers did

The Dutch NCSC saw exploitation attempts on 28 January 2026 and confirmed successful compromises at several organisations on 29 January, the day Ivanti published its advisory, with indications of data exfiltration. Forensic work in February showed the flaws had already been abused successfully in a similar way in August 2025. BSI also has indications that exploitation may have been going on since at least summer 2025.

Letters to the Dutch parliament named the organisations where traces of abuse were found or could not be ruled out: the Data Protection Authority (AP), the Council for the Judiciary, the prison service DJI, the return service DT&V, the justice IT organisation JIO, the Medicines Evaluation Board (CBG) and one municipality. At DJI, staff names, business contact details and location data were viewed by unauthorised persons. In Germany, BSI cited Shadowserver detecting more than 20 compromised organisations and expects the real number to be considerably higher.

After a proof of concept appeared on 30 January, the opportunists joined in. Shadowserver counted more than 28,000 source IP addresses attempting exploitation on 9 February alone. Unit 42 saw attempts to open reverse shells and install cryptominers and web shells, including dormant backdoors meant to survive patching.

Why patching was not the end of it

Ivanti’s edge products have been here before. APT actors exploited the EPMM zero-day CVE-2023-35078 from at least April to July 2023 to get into a Norwegian government network, and CISA listed exploited flaws in Ivanti Connect Secure VPN appliances in January 2024, January 2025 and April 2025. MDM servers and VPN appliances face the internet, hold the keys to much of the network, and are rarely watched as closely as ordinary servers.

The timeline is the real lesson. An organisation that patched on 29 January may have hosted an attacker since August, and stolen credentials stay stolen. On 7 May 2026 BSI warned of attacks through a new EPMM flaw, CVE-2026-6973, which requires admin credentials that may have been taken in the January attacks. Ivanti said customers who rotated credentials after January face a significantly lower risk from it. As of 1 October 2026, none of the agencies or vendors cited here has named the attackers.

What to do now

  • Check that EPMM runs 12.6.1.1, 12.7.0.1, 12.8.0.1 or later. The January RPM hotfix also closes both flaws, but an upgrade to another vulnerable version removes it.
  • Assume breach. Run the Exploitation Detection RPM that Ivanti built with the NCSC and search the logs as far back as you can, preferably in a SIEM, since attackers may have wiped local logs. BSI advises covering at least July 2025 onwards. No hits does not prove the appliance is clean.
  • If you find signs of compromise, do not clean the appliance yourself. Ivanti and BSI advise rebuilding it and migrating the data. Check Ivanti Sentry as well.
  • Replace what the server held: every credential linked to the appliance (admin, LDAP and service accounts), appliance certificates and issued tokens. Treat the data in the MIFS database as leaked.
  • Do not expose the EPMM admin interface to the internet; BSI names restricting access through a VPN as an extra safeguard. See also security misconfiguration.

Sources

Frequently asked questions

Is Ivanti's cloud MDM affected too?

No. Ivanti says only the on-premises EPMM is vulnerable, not Ivanti Neurons for MDM or Ivanti EPM. Sentry is not vulnerable either, but Ivanti advises reviewing it alongside EPMM because it depends on EPMM's configuration.

We patched on 29 January. Are we safe?

Not necessarily. The NCSC found successful abuse as early as August 2025, and an attacker who got in before the patch keeps that access afterwards. NCSC and BSI both advise assuming compromise and investigating until you can rule it out.

Can an attacker control our phones through EPMM?

According to Ivanti, EPMM cannot be used to run commands on managed devices, and private certificates cannot leave the phone. The real damage is the data and credentials on the server. Ivanti and BSI still advise checking for new admins, apps and policies pushed to devices.

Related articles

Press / to search · Esc