Critical Known exploited (KEV) CVE-2026-1340

Code Injection in Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1340) — Unauthenticated Remote Code Execution; the Mobile-Device-Management Platform as Target

Ivanti Endpoint Manager Mobile (EPMM) Added to KEV Apr 8, 2026 Federal remediation due 2026-04-11

Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core), a mobile-device-management (MDM) platform, contains a code injection flaw (CWE-94) that lets an unauthenticated attacker run arbitrary code remotely. CISA added it to the KEV on 2026-04-08, due 2026-04-11 (3 days). The CVSS published on NVD is 9.8 (CRITICAL).

Key facts

  • CVE IDCVE-2026-1340
  • CVSS base score9.8 CRITICAL
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Affected (vendor / product)Ivanti Endpoint Manager Mobile (EPMM)
  • CWECWE-94
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-04-11 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Code injection (CWE-94) in Ivanti EPMM (formerly MobileIron Core) — unauthenticated remote code execution.
  • The vector is PR:N and UI:N — no privilege and no user interaction required. The CVSS published on NVD is 9.8 (CRITICAL).
  • An MDM platform is the distribution source to the device fleet — a single breach can spread to the whole company's mobile estate.
  • EPMM is often internet-facing and thus easy to reach; Ivanti products are KEV regulars.
  • CISA added it to the KEV on 2026-04-08, due 2026-04-11 (3 days), and asks for a check for signs of compromise.
  • An MDM platform stands on the distributing side, so taking it propagates across the whole managed fleet.

1What code injection is

Code injection (CWE-94) is a flaw in which an attacker slips code (commands) into input that should be treated purely as data, and the system executes it. Without adequate validation and separation of input, an attacker can run the injected code on the server — effectively taking over the machine.

What makes this severe is that it is said to be possible on Ivanti EPMM without authentication (no login), as the vector's PR:N (no privilege required) and UI:N (no user interaction) confirm.

2The weight of an MDM platform

That the target is an MDM (mobile-device-management) platform is decisive for the weight of this flaw. EPMM functions as the distribution source that pushes settings, certificates, and apps to the many smartphones and tablets an organization deploys.

Seize that source without authentication and the impact is not confined to one device but can propagate across the entire managed fleet — a single breach spreading to the whole company's mobile estate. EPMM is also often placed facing the internet so that devices outside the office can check in at any time, making it easy for attackers to reach.

3Why Ivanti products keep being targeted

Ivanti products (EPMM, Connect Secure, and others) have been KEV regulars in recent years, emblematic of how boundary and management products are targeted again and again. CISA set the remediation window to just three days after the addition and additionally asks organizations to "check for signs of compromise" — i.e., respond on the assumption that exploitation is already underway.

The response is prompt updating per Ivanti's guidance, together with checking whether compromise has occurred.

4Taking the source of distribution

That the subject is an MDM platform is what settles the weight here. EPMM stands on the side that distributes to devices, so control of it spreads differently.

  1. 1Take the distribution sourceEPMM is what pushes configuration, certificates and applications out
  2. 2It reaches the managed fleetNot one device taken but the whole managed fleet exposed
  3. 3It is easy to reachOften placed facing the internet so that off-site devices can check in
  4. 4One breach reaches the whole organisationReachability and distribution privilege coincide

That it can succeed unauthenticated is severe in itself, and the vector's PR:N and UI:N confirm it. CISA set the deadline three days after listing and asked in addition that organisations check for signs of compromise — the response is framed on the assumption that exploitation has already occurred.

Why it matters

Unauthenticated code execution on an MDM platform has an extremely wide blast radius, propagating across the entire managed device fleet. EPMM is often internet-facing and will be targeted continuously if left unaddressed. CISA pairing a 3-day deadline with a request to check for signs of compromise indicates the response must assume exploitation is already advancing. Prompt updating per Ivanti's guidance, together with verifying impact and strengthening monitoring, is the key point.

FAQ

What is code injection?
A flaw where an attacker slips commands into input that should be treated as data and the system executes them. With insufficient validation/separation of input, the injected code runs on the server, leading to takeover of the machine.
Why is targeting an MDM platform a problem?
An MDM is the distribution source that pushes settings, certificates, and apps to many devices. Seize it and the damage is not confined to one device but can propagate across the entire managed fleet, making the impact especially large.
Could it already be exploited?
CISA added it to the KEV (flaws confirmed exploited in the wild) and asks organizations to check for signs of compromise. Respond on the assumption exploitation is already underway, updating and verifying impact promptly.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Ivanti#EPMM#MobileIron#CWE-94#Code Injection#MDM#KEV
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.