Description
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CISA Known Exploited Vulnerability
Date added 2026-01-29 | Due date 2026-02-01
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
12.x.1.x RPM (custom)
12.x.0.x RPM (custom)
References
www.cisa.gov/...nerabilities-catalog?field_cve=CVE-2026-1281
forums.ivanti.com/...Mobile-EPMM-CVE-2026-1281-CVE-2026-1340