CVE-2026-1340 is a critical code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthenticated remote code execution. With a CVSS score of 9.8, this flaw is easily exploitable over the network without user interaction, leading to complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, with public exploit modules available and significant community discussion, including links to government breaches. This high-risk vulnerability has been widely reported in media, highlighting its severe impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12.7.0.0CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.