CVE-2026-1281 & CVE-2026-1340
嗯,用户让我用中文帮他总结一篇文章,控制在100个字以内,而且不需要用“文章内容总结”这样的开头。我先看看这篇文章讲的是什么。 文章标题是关于Ivanti Endpoint Manager Mobile的两个漏洞,CVE-2026-1281和CVE-2026-1340,都是远程代码执行的高危漏洞。CVSS评分是9.8,属于严重级别。这些漏洞已经被积极利用作为零日攻击,影响了很多组织。 文章还提到这些漏洞允许未经身份验证的攻击者通过精心构造的HTTP请求执行任意代码,可能导致设备和数据被入侵。修复方法是应用特定的RPM更新,并建议用户运行快速响应测试来确认漏洞是否被修复。 用户的需求是让文章内容简洁明了地呈现出来,不超过100字。我需要抓住关键点:漏洞名称、影响、CVSS评分、攻击方式、后果以及修复措施。 可能需要排除一些技术细节,比如攻击向量、用户交互等,这些可能在总结中不太重要。重点放在漏洞的影响和修复上。 所以总结应该包括:两个漏洞名称,影响Ivanti EPMM系统,CVSS 9.8分,远程代码执行风险,零日攻击已发生,建议立即更新补丁。 </think> Ivanti Endpoint Manager Mobile存在两个高危远程代码执行漏洞(CVE-2026-1281和CVE-2026-1340),CVSS评分9.8分。攻击者可通过构造HTTP请求在未认证情况下执行任意代码。这些漏洞已被用于零日攻击,建议受影响组织立即应用补丁修复以降低风险。 2026-2-11 21:55:51 Author: horizon3.ai(查看原文) 阅读量:2 收藏

Ivanti Endpoint Manager Mobile | Actively Exploited Remote Code Execution

CVE-2026-1281 and CVE-2026-1340 are critical code injection vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM). The vulnerabilities allow unauthenticated remote code execution via specially crafted HTTP requests. Both carry a CVSS v3 score of 9.8.

Ivanti confirmed that these vulnerabilities have been actively exploited as zero-days in the wild. CVE-2026-1281 has been added to CISA’s Known Exploited Vulnerabilities catalog. Organizations running exposed or unpatched EPMM instances should treat this as an immediate risk.

Successful exploitation allows an attacker to execute arbitrary code on the vulnerable system, potentially leading to full compromise of the EPMM appliance, unauthorized access to managed mobile devices and enterprise data, and lateral movement into connected systems.

Stop Guessing, Start Proving

NodeZero Rapid Response test for CVE-2026-1281 and CVE-2026-1340 Ivanti Endpoint Manager Mobile remote code execution vulnerabilities

Technical Details

The vulnerabilities stem from improper handling and validation of HTTP requests within Ivanti Endpoint Manager Mobile. Specially crafted requests can trigger remote code execution without authentication.

Attack characteristics:

  • Attack vector: Network
  • Authentication required: None
  • User interaction: None
  • Impact: Remote code execution
  • CVSS v3 score: 9.8
  • Exploitation status: Actively exploited

Because EPMM often manages corporate devices, credentials, VPN access, and enterprise applications, compromise can have cascading downstream impact across identity systems and internal infrastructure.

NodeZero® Offensive Security Platform — Rapid Response

To safely verify if CVE-2026-1281 and CVE-2026-1340 affect Ivanti EPMM instances, Horizon3.ai customers can take advantage of the newly released Rapid Response test to confirm exploitability and remediation after patching.

  • Run the Rapid Response test — Launch the Ivanti EPMM CVE-2026-1281 & CVE-2026-1340 Rapid Response test from the customer portal to assess internet-facing and internal EPMM instances for exploitable RCE exposure.
  • Apply mitigation immediately — Follow Ivanti’s security advisory guidance and apply the appropriate RPM update based on your installed version. Customers should apply either RPM 12.x.0.x or RPM 12.x.1.x depending on their version. Only one RPM is required per version.
  • Re-run the Rapid Response test — Validate that exploitation is no longer possible and confirm mitigation has effectively removed exposure.

Rapid Response helps security teams focus on vulnerabilities attackers are actively targeting, allowing prioritized action based on validated exposure.

Indicators of Compromise

Ivanti has published detection guidance, including log review and regular expression-based detection methods, in its advisory. Organizations should monitor for:

  • Suspicious or malformed HTTP requests targeting EPMM services
  • Unexpected process execution on EPMM hosts
  • Unauthorized configuration changes within the EPMM console
  • Unusual outbound network connections originating from EPMM servers

Given confirmed exploitation, exposed systems should be reviewed for compromise immediately.

Affected Versions

  • Ivanti Endpoint Manager Mobile versions 12.5.0.0 and prior
  • Ivanti Endpoint Manager Mobile versions 12.5.1.0 and prior
  • Ivanti Endpoint Manager Mobile versions 12.6.0.0 and prior
  • Ivanti Endpoint Manager Mobile versions 12.6.1.0 and prior
  • Ivanti Endpoint Manager Mobile versions 12.7.0.0 and prior

Fixed Versions / Mitigation

  • Mitigation: Apply the appropriate RPM update as outlined in the Ivanti Security Advisory. Customers must apply either RPM 12.x.0.x or RPM 12.x.1.x depending on their installed version. The RPMs are version-specific, not vulnerability-specific.
  • Permanent fix: A full fix is expected in product release version 12.8.0.0, scheduled for release in Q1 2026.

References

Read about other CVEs

NodeZero® Platform

Implement a continuous find, fix, and verify loop with NodeZero

The NodeZero® platform empowers your organization to reduce your security risks by autonomously finding exploitable weaknesses in your network, giving you detailed guidance around how to priortize and fix them, and having you immediately verify that your fixes are effective.

Explore NodeZero

Recognized By


文章来源: https://horizon3.ai/attack-research/vulnerabilities/cve-2026-1281-cve-2026-1340/
如有侵权请联系:admin#unsafe.sh