Tech »  Topic »  January blues return as Ivanti coughs up exploited EPMM zero-days

January blues return as Ivanti coughs up exploited EPMM zero-days


Ivanti has patched two critical zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM) product that are already being exploited, continuing a grim run of January security incidents for enterprise IT vendors.

In January 2025, tens of thousands were urged to patch a Fortinet zero-day, while Ivanti customers were doing the same. There has been little change this year as Fortinet patches multiple single sign-on (SSO) flaws and Ivanti ships fixes for yet another pair of zero-days.

Tracked as CVE-2026-1281 and CVE-2026-1340, both bugs affect Ivanti Endpoint Manager Mobile (EPMM). They're also both rated a near-maximum CVSS score of 9.8 and allow for unauthenticated remote code execution (RCE) – about as bad as it gets.

The security shop said in its advisory: "We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure.

"This vulnerability does not impact any other Ivanti ...


Copyright of this story solely belongs to theregister.co.uk . To see the full text click HERE