Story perspectives
Ivanti Releases Critical Updates for Two Major Vulnerabilities
1/30/2026
1 of 1
Story summary
- Ivanti, the software company behind Endpoint Manager Mobile (EPMM), released updates for two critical vulnerabilities, CVE-2026-1281 and CVE-2026-1340, enabling unauthenticated remote code execution.
- The flaws were added to the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog.
- Users should check logs for exploitation signs and reapply patches after upgrading.
- Ivanti plans a permanent fix in version 12.8.0.0, slated for release in Q1 2026, and notes limited exploitation among customers.
