Vulnerability threat dossier

CVE-2026-1281

ivantiendpoint manager mobile

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

VTP deterministic threat66.7of 100 · CVSS excluded

VTP analyst assessment

Ivanti EPMM unauthenticated remote code execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityCRITICAL
AI confidence96%
Public exploitation · VTP factKEV

Assessment

CVE-2026-1281 is an unauthenticated code-injection flaw in Ivanti Endpoint Manager Mobile. CISA KEV and ENISA EU KEV list it as known exploited, and public exploit-template coverage is available.

Why it matters

  • A network-reachable affected EPMM system could allow an unauthenticated attacker to execute code.
  • If you use EPMM 12.5.1.0 or 12.6.0.0, apply Ivanti remediation urgently and restrict management-service exposure.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The sources do not describe the exploit chain, targeting, or customer impact.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Identify affected EPMM versions and externally reachable management interfaces.

AI baseline history (5)
  1. BASELINE ASSESSED
    Ivanti EPMM unauthenticated remote code executiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    Ivanti EPMM unauthenticated code injectiongpt-5.6-terra · low
  3. BASELINE ASSESSED
    Ivanti EPMM unauthenticated code injectiongpt-5.6-terra · low
  4. BASELINE ASSESSED
    Ivanti EPMM unauthenticated code injectiongpt-5.6-sol · high
  5. BASELINE ASSESSED
    Ivanti EPMM unauthenticated code injectiongpt-5.6-sol · high
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.99100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 0.99; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

3publications detected
3underlying evidence chains

1 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:NUCLEI:26219f2472b9580106c077336f6ae771f3dbd133ACTIVE
Evidence
Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-1281ACTIVE
Evidence
04

Event history

Threat timeline

  1. 14:5916 Sept
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-1281.

  2. 09:1015 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    ProjectDiscovery nuclei-templates published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  3. 00:0029 Jan
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

  4. 00:0029 Jan
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

05

Original publications

Source record

Nuclei Templates v10.4.9 - Release Notes

New Templates Added: 123 | CVEs Added: 85 | First-time contributions: 15 🔥 Release Highlights 🔥 [ CVE-2026-86207 ] N-able N-central - Authentication Bypass ( @rapid7 , @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-85706 ] GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File Read ( @flx ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-83548 ] SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB ( @rapid7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-82329 ] JFrog Artifactory Access Blank Join Key Authentication Bypass ( @johnk3r , @pruva ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-82222 ] GiveWP <= 4.16.7.1 - Remote Code Execution (@0x_Akoko, @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-81578 ] PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct ( @darses , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-73570 ] Zimbra Collaboration Suite < 10.1.20 - OS Command Injection (@0x_Akoko, @ritikchaddha ) [high] (kev) (vKEV) 🔥 [ CVE-2026-55040 ] Microsoft SharePoint Server - JWT Authentication Bypass ( @sfewer-r7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-48558 ] SimpleHelp <=5.5.15 - OIDC JWT Authentication Bypass (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-41948 ] Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-32475 ] Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler ( @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-18963 ] Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-18577 ] N-able N-central < 2026.3.1.10 - Authentication Bypass ( @patrick-threatmate ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-9586 ] Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-1281 ] Ivanti EPMM <=12.7.0.0 - Unauthenticated Code Injection ( @rxerium ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-0768 ] Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_code ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2024-1708 ] ConnectWise ScreenConnect <= 23.9.7 - Path Traversal ( @Popy21 ) [high] (kev) (vKEV) 🔥 [ CVE-2023-54391 ] Proxmox VE - Default Credentials with TFA Bypass ( @dhiyaneshdk , @0x_Akoko) [critical] (vKEV) 🔥 [ CVE-2020-10221 ] rConfig <= 3.9.4 - Authenticated OS Command Injection ( @Jayachandran from Securin Labs ( https://securin.io )) [high] (kev) (vKEV) 🔥 [ CVE-2019-11043 ] PHP-FPM Path Info Buffer Underflow - Remote Code Execution ( @prasath from Securin Labs ( https://securin.io )) [critical] (kev) (vKEV) 🔥 [ CVE-2017-7504 ] JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization ( @Jayachandran ) [critical] (vKEV) 🔥 What's Changed Bug Fixes Fixed the CVE-2026-41042 template filename so the template loads correctly (PR #17024 , Issue #17022 ). Corrected the filename casing on CVE-2025-14047 .yaml (PR #16994 ). Resolved an unresolved nested payload variable in CVE-2026-4257 that stopped the WordPress Contact Form by Supsystic template running on nuclei v3.11.1 (PR #17039 ). Fixed the matched_feature extractor in CVE-2026-76904 .yaml (PR #16969 ). Corrected the author field in CVE-2026-61511 .yaml (PR #16976 ). Removed six imprecise CVE templates whose proofs of concept were not reliable — CVE-2016-3714 , CVE-2018-10933 , CVE-2018-15708 , CVE-2019-8942 , CVE-2019-17554 and CVE-2020-2555 (PR #16567 ). False Negatives CVE-2021-43798 — the Grafana arbitrary file read template now fires on instances sitting behind an nginx reverse proxy (PR #17185 ). CVE-2018-3760 — restored broken detection on Ruby on Rails local file inclusion using disable-path-automerge and a flow block (PR #17235 ). CVE-2021-34429 — replaced unsafe with disable-path-automerge so the Jetty request path is no longer duplicated (PR #17236 ). CVE-2024-52433 — the My Geo Posts Free template could never match a genuin

CVE-2016-3714CVE-2017-7504CVE-2017-8225CVE-2018-10933CVE-2018-15708CVE-2018-3760CVE-2019-11043CVE-2019-17554CVE-2019-8942CVE-2020-10221CVE-2020-2555CVE-2020-29134CVE-2021-34429CVE-2021-43798CVE-2022-39258CVE-2023-54391CVE-2024-1708CVE-2024-52433CVE-2025-14047CVE-2025-14998CVE-2025-15403CVE-2025-29927CVE-2025-51683CVE-2025-53887CVE-2025-57231CVE-2026-0561CVE-2026-0650CVE-2026-0702CVE-2026-0743CVE-2026-0768CVE-2026-11801CVE-2026-1281CVE-2026-12898CVE-2026-18577CVE-2026-18963CVE-2026-19092CVE-2026-19632CVE-2026-2113CVE-2026-21875CVE-2026-23491CVE-2026-23536CVE-2026-23693CVE-2026-26265CVE-2026-27454CVE-2026-27960CVE-2026-28141CVE-2026-28411CVE-2026-29962CVE-2026-29963CVE-2026-30849CVE-2026-32475CVE-2026-33017CVE-2026-34234CVE-2026-41042CVE-2026-41452CVE-2026-41456CVE-2026-41679CVE-2026-41948CVE-2026-42221CVE-2026-4257CVE-2026-42596CVE-2026-42878CVE-2026-44177CVE-2026-44343CVE-2026-48558CVE-2026-53595CVE-2026-55040CVE-2026-55229CVE-2026-5524CVE-2026-5562CVE-2026-56292CVE-2026-57582CVE-2026-58123CVE-2026-58191CVE-2026-59177CVE-2026-59509CVE-2026-59726CVE-2026-60105CVE-2026-61511CVE-2026-61736CVE-2026-62382CVE-2026-65761CVE-2026-72898CVE-2026-73034CVE-2026-73570CVE-2026-7467CVE-2026-76904CVE-2026-77806CVE-2026-81199CVE-2026-81578CVE-2026-82222CVE-2026-82329CVE-2026-83548CVE-2026-8467CVE-2026-85200CVE-2026-85706CVE-2026-86206CVE-2026-86207CVE-2026-86426CVE-2026-87820CVE-2026-88062CVE-2026-9133CVE-2026-9586
Separate evidence group
Original

Exploit tooling coverage changed for 4 CVEs

ProjectDiscovery nuclei-templates recorded exploit-tooling coverage changes for 4 CVEs in this pinned revision. 4 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2026-0768CVE-2026-1281CVE-2026-5524CVE-2026-59726
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-1281

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-1281
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score66.7vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction19.71 / 20
Exploit availability7.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-94
CPE records
5
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.