Attackers are exploiting critical unauthenticated remote code execution vulnerabilities CVE-2026-1281 and CVE-2026-1340 in Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core. Both flaws carry CVSS scores of 9.8 and stem from unsafe handling of attacker-controlled input in Bash scripts invoked through Apache RewriteMap. Telekom Security responders observed command-execution checks, JSP webshell deployment, reverse-shell attempts, secondary malware delivery, and database export attempts across multiple customer environments. CrowdSec reported exploitation-related activity increasing in early February and a small number of attackers targeting more than 500 distinct machines, without establishing how many were compromised; CVE-2026-1281 was also added to CISA’s Known Exploited Vulnerabilities catalog.
Public reporting indicates exploitation across multiple countries and sectors, while Germany’s BSI warned that attacks may have begun as early as summer 2025, before the flaws’ January 2026 disclosure. Patching alone does not remove previously established persistence. Organizations should apply current Ivanti patches, verify that RPM-based mitigations persist after reboots, restrict appliance access through a VPN, and assess systems using published detection guidance. Response teams should investigate webshells and other persistence, possible credential theft, data exfiltration, and lateral movement, and follow vendor guidance on upgrading to EPMM 12.8.0.0.

See which actors are running it and whether you're in range.
14 events from the most recent confirmed update back to the earliest known activity.
CrowdSec identified February 4 as the start of its observed active exploitation of CVE-2026-1281. Its telemetry showed a small number of attackers targeting more than 500 distinct machines, without establishing how many were successfully compromised.
CrowdSec telemetry indicated exploitation-related activity increasing around February 2, shortly after public disclosure of the EPMM vulnerabilities.
Ivanti disclosed CVE-2026-1281 and CVE-2026-1340 alongside emergency mitigation guidance. Both vulnerabilities carry CVSS scores of 9.8 and allow unauthenticated remote code execution on reachable vulnerable appliances.
Germany’s BSI warned that exploitation of the Ivanti EPMM vulnerabilities may have occurred since at least summer 2025. This was a possible earlier exploitation period, not a confirmed start date.
BSI confirmed targeting of German organizations and cited Shadowserver detection of more than 20 compromised organizations in Germany. It published compromise indicators and advised operators to assume possible compromise even if they patched on disclosure day, because patching does not remove existing persistence.
Defused separately described a /mifs/403.jsp backdoor that executes Base64-encoded Java bytecode in memory. The backdoor is triggered by requests containing the HTTP header k0f53cf964d387.
Unit 42 reported exploitation affecting organizations in the United States, Germany, Australia, and Canada across government, healthcare, manufacturing, services, and technology. It described predominantly automated activity involving webshells, malware downloads, and dormant backdoors intended to retain access after patching.
Attackers attempted to export EPMM database tables containing user, LDAP, device, configuration, and password-history information into a web-accessible directory. They also attempted to archive system files for possible exfiltration, but the reporting did not confirm data transfer.
Responders observed an attacker write a Base64-decoded ELF payload named sysd, make it executable, and launch it. Preliminary analysis identified file read/write activity, dropped files, and outbound contact to 217.148.142[.]48.
Incident responders investigated multiple customer environments and found successful command execution, JSP webshells including 401.jsp and 403.jsp, and reverse shell attempts. They withheld attribution because activity from multiple actors and botnets overlapped.
CISA added CVE-2026-1281 to its Known Exploited Vulnerabilities catalog, recognizing exploitation in the wild.
WatchTowr demonstrated arbitrary command execution as the web server user through crafted URL parameters. Its technical reporting explained Bash arithmetic command substitution and the padding needed to bypass a string-length validation check.
Ivanti released RPM patches addressing the vulnerable URL mappings. The patches replace Bash-based Apache RewriteMap handlers with Java implementations.
WatchTowr Labs discovered an unauthenticated remote code execution vulnerability in Ivanti EPMM involving inadequately sanitized input processed by a Bash URL-mapping script.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.