Code Injection in Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1340) — Unauthenticated Remote Code Execution; the Mobile-Device-Management Platform as Target
Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core), a mobile-device-management (MDM) platform, contains a code injection flaw (CWE-94) that lets an unauthenticated attacker run arbitrary code remotely. CISA added it to the KEV on 2026-04-08, due 2026-04-11 (3 days). The CVSS published on NVD is 9.8 (CRITICAL).
Key facts
- CVE IDCVE-2026-1340
- CVSS base score9.8 CRITICAL
- CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Affected (vendor / product)Ivanti Endpoint Manager Mobile (EPMM)
- CWECWE-94
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-04-11 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Code injection (CWE-94) in Ivanti EPMM (formerly MobileIron Core) — unauthenticated remote code execution.
- The vector is PR:N and UI:N — no privilege and no user interaction required. The CVSS published on NVD is 9.8 (CRITICAL).
- An MDM platform is the distribution source to the device fleet — a single breach can spread to the whole company's mobile estate.
- EPMM is often internet-facing and thus easy to reach; Ivanti products are KEV regulars.
- CISA added it to the KEV on 2026-04-08, due 2026-04-11 (3 days), and asks for a check for signs of compromise.
Code injection (CWE-94) is a flaw in which an attacker slips code (commands) into input that should be treated purely as data, and the system executes it. Without adequate validation and separation of input, an attacker can run the injected code on the server — effectively taking over the machine.
What makes this severe is that it is said to be possible on Ivanti EPMM without authentication (no login), as the vector's PR:N (no privilege required) and UI:N (no user interaction) confirm.
That the target is an MDM (mobile-device-management) platform is decisive for the weight of this flaw. EPMM functions as the distribution source that pushes settings, certificates, and apps to the many smartphones and tablets an organization deploys.
Seize that source without authentication and the impact is not confined to one device but can propagate across the entire managed fleet — a single breach spreading to the whole company's mobile estate. EPMM is also often placed facing the internet so that devices outside the office can check in at any time, making it easy for attackers to reach.
Ivanti products (EPMM, Connect Secure, and others) have been KEV regulars in recent years, emblematic of how boundary and management products are targeted again and again. CISA set the remediation window to just three days after the addition and additionally asks organizations to "check for signs of compromise" — i.e., respond on the assumption that exploitation is already underway.
The response is prompt updating per Ivanti's guidance, together with checking whether compromise has occurred.
Why it matters
Unauthenticated code execution on an MDM platform has an extremely wide blast radius, propagating across the entire managed device fleet. EPMM is often internet-facing and will be targeted continuously if left unaddressed. CISA pairing a 3-day deadline with a request to check for signs of compromise indicates the response must assume exploitation is already advancing. Prompt updating per Ivanti's guidance, together with verifying impact and strengthening monitoring, is the key point.
FAQ
What is code injection?
Why is targeting an MDM platform a problem?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).