Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ivanti disclosed on January 29, 2026, that two critical flaws in its on-premises Endpoint Manager Mobile (EPMM) product—CVE-2026-1281 and CVE-2026-1340—were being exploited as zero-days. Both can allow unauthenticated remote code execution on a vulnerable appliance. The original fixes addressed those flaws, but later EPMM security updates have since appeared; administrators should match their exact build to Ivanti’s current advisory rather than treat the January mitigation as current patch policy.

What happened in the Ivanti EPMM zero-day attacks?

The two vulnerabilities are code-injection flaws rated CVSS v3.1 9.8 out of 10 each by Singapore’s Cyber Security Agency (CSA). CERT-EU’s January 30, 2026 advisory said one had been exploited in a limited number of cases at that time. Ivanti also described a very limited number of affected customers at disclosure, as reported by BleepingComputer on January 29, 2026. These early reports should not be read as a final count of victims.

Later, Palo Alto Networks Unit 42 described active exploitation of both flaws and reported identifying more than 4,400 EPMM instances in its own telemetry. That figure is a telemetry observation, not a global census or a count of compromised organizations. Unit 42 reported reverse-shell attempts, web shells, reconnaissance, and malware-download activity, indicating that some attackers moved beyond probing vulnerable endpoints. Unit 42’s February 17, 2026 analysis provides the technical account.

What the flaws affect

Unit 42 describes CVE-2026-1281 as involving legacy Bash scripts used in Apache URL rewriting for EPMM’s In-House Application Distribution feature. CVE-2026-1340 affects the Android File Transfer mechanism and uses a separate endpoint and script. Both attack paths concern an EPMM appliance exposed to unauthenticated requests; the disclosures do not establish that every exposed system was successfully compromised.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Why a compromised appliance matters

EPMM manages mobile devices, so an intrusion could expose administrator or user names, email addresses, phone numbers, IP addresses, device identifiers, installed-app details, and location data where tracking is enabled. An attacker with access to the appliance could also alter device configuration, including authentication settings. These are potential consequences, not proof that any particular victim’s data was accessed.

Which Ivanti EPMM versions are affected?

Published summaries describe the affected releases using slightly different version-range formats. CSA lists EPMM 12.5.0.x, 12.6.0.x, 12.7.0.x, 12.5.1.0, and 12.6.1.0. CERT-EU describes 12.5.1.0 and prior, 12.6.1.0 and prior, and 12.7.0.0 and prior. Check the precise build against Ivanti’s live advisory before deciding that an appliance is affected or fixed.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

For the January flaws, Ivanti’s cumulative release notes list CVE-2026-1281 and CVE-2026-1340 as fixed in EPMM 12.8.0.0. However, Ivanti published additional EPMM security updates by September 2026, including fixes for a later issue in 12.10.0.0, 12.9.0.2, and 12.8.0.4. Therefore, 12.8.0.0 identifies a release that fixed the January pair; it does not establish that this is the newest secure release for an environment today. Consult Ivanti’s current EPMM advisories and supported-release notes for the applicable branch and current fix.

How should administrators patch CVE-2026-1281 and CVE-2026-1340?

Ivanti’s initial remediation used version-specific RPM mitigations. CSA documented this mapping at disclosure:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
EPMM version at disclosure Corresponding interim RPM
12.5.0.x, 12.6.0.x, or 12.7.0.x RPM 12.x.0.x
12.5.1.0 or 12.6.1.0 RPM 12.x.1.x

The RPMs were specific to the EPMM version. CSA warned that a hotfix would not survive a version upgrade and would have to be reapplied if the appliance was upgraded before the permanent fix. These January instructions are historical, not a substitute for checking the current vendor guidance.

  1. Identify the exact build and branch. Record the EPMM version and compare it with Ivanti’s current advisory and supported-release information.
  2. Apply the current vendor-recommended fix for that branch. Do not select an RPM based only on the broad 12.5, 12.6, or 12.7 family; use the exact version-specific directions Ivanti provides.
  3. Recheck after an upgrade. If using an interim mitigation during an upgrade, confirm whether it must be reapplied. The original hotfixes did not persist through an EPMM version upgrade.
  4. Verify the resulting version and mitigation state. Confirm that the appliance is on a release Ivanti identifies as fixed for the relevant vulnerabilities and any later issues affecting the environment.

How can you tell whether an EPMM appliance was compromised?

One detection lead reported by BleepingComputer is attempts to reach the relevant application-distribution and Android File Transfer endpoints in the Apache access log. Ivanti supplied a regular expression to identify external requests to vulnerable paths that returned HTTP 404; the report contrasts these with legitimate requests that typically return HTTP 200. Use that pattern only as one indicator, not as a complete compromise test. A missing matching request does not prove the appliance was safe, and logs could have been altered or deleted after an intrusion.

Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Review off-device logs if available, preserve relevant evidence, and investigate the appliance as well as systems it can access. Ivanti’s reported advice, quoted by BleepingComputer, was to review systems Sentry can access for possible reconnaissance or lateral movement when an appliance is suspected to be affected. Unit 42’s reported signs—including reverse shells, web shells, reconnaissance, and malware-download or persistence attempts—can inform an investigation, but do not replace Ivanti’s latest incident guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should you do if compromise is suspected?

Installing a fix prevents exploitation of the fixed vulnerability going forward; it does not show whether attackers accessed the appliance beforehand. Ivanti reportedly recommended against trying to clean a suspected compromised EPMM system. BleepingComputer’s account of Ivanti’s guidance describes restoring from a known-good pre-compromise backup or rebuilding and migrating data to a replacement system, followed by steps such as resetting local and integrated-service account passwords and revoking and replacing the public EPMM certificate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Those actions are not a complete incident plan for every environment. Preserve evidence and follow Ivanti’s current advisory and recovery guidance; involve your incident-response team or qualified responders where appropriate. The right recovery path depends on the evidence, the appliance’s role, and the systems and credentials it could reach.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.