AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityCRITICAL
AI confidence97%
Public exploitation · VTP factKEV
Assessment
CVE-2026-1340 is an unauthenticated code-injection flaw in Ivanti Endpoint Manager Mobile that enables remote code execution. CISA KEV and ENISA EU KEV list known exploitation. ProjectDiscovery also provides public template coverage.
Why it matters
An attacker who can reach a vulnerable EPMM service could execute code without authentication.
EPMM manages mobile endpoints, so compromise could expose a management service and its connected environment.
Evidence
2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.
Uncertainties
The supplied reports do not identify targets, affected deployments, or a specific exploitation method.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Next watchpoint
If you use Ivanti EPMM, apply Ivanti's fix on vulnerable instances as a priority.
AI baseline history (4)
BASELINE ASSESSED
Ivanti Endpoint Manager Mobile code injectiongpt-5.6-terra · low
BASELINE ASSESSED
Ivanti EPMM code injectiongpt-5.6-terra · low
BASELINE ASSESSED
Ivanti EPMM unauthenticated code injectiongpt-5.6-sol · high
BASELINE ASSESSED
Ivanti EPMM unauthenticated code injectiongpt-5.6-sol · high
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
CISA KEV lists this vulnerability as known to be exploited globally.
02
A proof of concept is reported; functional reliability is not established.
03
EPSS is 0.99; this is predictive context, not exploitation evidence.
04
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
02
Material change ledger
What changed
EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
03
Claim provenance
Evidence and source independence
2publications detected
2underlying evidence chains
1 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
ProjectDiscovery nuclei-templates published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.
00:0008 Apr
KEV ADDED
CISA KEV entry added
CISA lists global known exploitation. This is not a VTP sensor observation.
00:0029 Jan
ACTIVE EXPLOITATION
ENISA EU KEV entry added
ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.
ProjectDiscovery nuclei-templates recorded exploit-tooling coverage changes for 6 CVEs in this pinned revision. 6 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.