You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
ivanti epmm
About this tag
Ivanti EPMM (Endpoint Manager Mobile) is a mobile device management (MDM) product from Ivanti. Discussions on WindowsForum highlight recurring security vulnerabilities in Ivanti EPMM, including code injection and remote code execution flaws that have been actively exploited. CISA has added multiple Ivanti EPMM CVEs to its Known Exploited Vulnerabilities (KEV) catalog, such as CVE-2026-1340, CVE-2026-1281, and CVE-2025-4427/4428. These vulnerabilities allow unauthenticated attackers to execute code, install backdoors, and exfiltrate data via Tomcat listeners. The forum covers patch guidance, indicators of compromise (IOCs), and the urgency of applying updates, especially for organizations bound by BOD 22-01.
CISA’s latest addition to the Known Exploited Vulnerabilities Catalog is a reminder that the agency still sees active exploitation as the best signal for urgency, not just theoretical severity. On April 8, 2026, CISA added CVE-2026-1340, a code injection vulnerability in Ivanti Endpoint Manager...
StopICE, the volunteer-run tracker used by activists to monitor ICE movements, says a recent defacement and user-targeting incident was a targeted intimidation stunt that traced back to what administrators describe as “a personal server associated with a CBP agent here in SoCal,” but important...
CISA’s Known Exploited Vulnerabilities (KEV) Catalog has one more entry to worry about: on January 29, 2026 the agency added CVE-2026-1281, a code-injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM). The short version: this is a classic, high-risk attack vector in a mobile device...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has analyzed malicious “listener” malware actively deployed against Ivanti Endpoint Manager Mobile (EPMM) servers following public proof-of-concept exploit code for CVE-2025-4427 and CVE-2025-4428, and the resulting toolset allows...
CISA’s release of a Malware Analysis Report (MAR) detailing a Malicious Listener discovered on compromised Ivanti Endpoint Manager Mobile (EPMM) systems should reset priorities for every IT team that runs on-premises mobile device management (MDM). The analysis dissects two sets of malware...