CVE-2026-1340
Modified
Published: 29 Jan 2026, 21:33
Last modified:09 Apr 2026, 03:55
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
67.74% CRITICAL
68% probability 0.00%
KEV
Listed
CIRCL • CISA • ENISA
3 listings
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
29 Jan 2026, 21:33
Published
Vulnerability first disclosed
29 Jan 2026, 00:00
Added to ENISA KEV
Added to Known Exploited Vulnerabilities catalog
03 Feb 2026, 00:00
Added to CIRCL KEV
Added to Known Exploited Vulnerabilities catalog
08 Apr 2026, 00:00
Added to CISA KEV
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
09 Apr 2026, 03:55
Last Modified
Vulnerability information updated
11 Apr 2026, 00:00
CISA Remediation Due
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CVSS Metrics
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 67.74%• Percentile: 99%
Techniques & Countermeasures
- CWE-94•Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Affected Systems
- ivanti•endpoint manager mobile
≤ 12.7.0.0