---
id: CVE-2026-1281
title: >-
  A code injection in Ivanti Endpoint Manager Mobile allowing attackers to
  achieve unauthenticated remote code execution.
summary: >-
  A code injection in Ivanti Endpoint Manager Mobile allowing attackers to
  achieve unauthenticated remote code execution.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-94
vendor: Ivanti
product: Endpoint Manager Mobile
affected:
  - endpoint_manager_mobile (all versions)
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-01-30T04:55:43.957910Z'
exploited: true
exploitAvailable: true
published: '2026-01-29'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:00:12.330Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-1281'
references:
  - url: >-
      https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340
tags:
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
epss: 0.98688
epssPercentile: 0.99924
kev: true
kevDateAdded: '2026-01-29'
kevDueDate: '2026-02-01'
kevRansomware: false
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/MehdiLeDeaut/CVE-2026-1281-Ivanti-EPMM-RCE'
    - 'https://github.com/YunfeiGE18/CVE-2026-1281-CVE-2026-1340-Ivanti-EPMM-RCE'
  metasploit:
    - exploit/linux/http/ivanti_epmm_rce
  nuclei:
    - CVE-2026-1281
  checkedAt: '2026-10-07T18:42:55.499Z'
zeroDay: true
ingestedAt: '2026-10-07T18:42:20.911Z'
---

## Overview

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

## Affected

- `endpoint_manager_mobile (all versions)`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
