CVE-2026-1281

CRITICAL KEV

Ivanti Endpoint Manager Mobile (EPMM) unauthenticated RCE

Title source: metasploit

Description

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Exploits (3)

github SCANNER 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-1281
nomisec WORKING POC 2 stars
by MehdiLeDeaut · poc
https://github.com/MehdiLeDeaut/CVE-2026-1281-Ivanti-EPMM-RCE
nomisec WORKING POC 1 stars
by YunfeiGE18 · remote
https://github.com/YunfeiGE18/CVE-2026-1281-CVE-2026-1340-Ivanti-EPMM-RCE

Scores

CVSS v3 9.8
EPSS 0.7936
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2026-01-29
VulnCheck KEV 2026-01-29
ENISA EUVD EUVD-2026-4940
CWE
CWE-94
Status published
Products (5)
ivanti/endpoint_manager_mobile 12.5.1.0
ivanti/endpoint_manager_mobile 12.6.0.0
ivanti/endpoint_manager_mobile 12.6.1.0
ivanti/endpoint_manager_mobile 12.7.0.0
ivanti/endpoint_manager_mobile < 12.5.0.0
Published Jan 29, 2026
KEV Added Jan 29, 2026
Tracked Since Feb 18, 2026