CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 566

As cited

Copy frozen at (site build).

vulnerabilities

Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)

Ivanti released patches for two pre-authentication remote code execution vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in Endpoint Manager Mobile (EPMM), an enterprise mobility management platform used to control corporate mobile devices. The vulnerabilities are actively exploited in the wild and have been added to CISA's Known Exploited Vulnerabilities list. Permanent patches are not available until Q1 2026; customers are currently receiving temporary RPM patches that must be reapplied after system updates to remain effective.

Why it matters: Organizations running Ivanti EPMM are at immediate risk of unauthenticated remote code execution and must apply temporary patches now and monitor for active exploitation; failure to act leaves corporate mobile fleets and enterprise resources vulnerable to compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)

Ivanti released patches for two pre-authentication remote code execution vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in Endpoint Manager Mobile (EPMM), an enterprise mobility management platform used to control corporate mobile devices. The vulnerabilities are actively exploited in the wild and have been added to CISA's Known Exploited Vulnerabilities list. Permanent patches are not available until Q1 2026; customers are currently receiving temporary RPM patches that must be reapplied after system updates to remain effective.

Why it matters: Organizations running Ivanti EPMM are at immediate risk of unauthenticated remote code execution and must apply temporary patches now and monitor for active exploitation; failure to act leaves corporate mobile fleets and enterprise resources vulnerable to compromise.

VendorsAppleGoogleIvantiOracleF5
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary