Critical Known exploited (KEV) CVE-2026-1340

Code Injection in Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1340) — Unauthenticated Remote Code Execution; the Mobile-Device-Management Platform as Target

Ivanti Endpoint Manager Mobile (EPMM) Added to KEV Apr 8, 2026 Federal remediation due 2026-04-11

Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core), a mobile-device-management (MDM) platform, contains a code injection flaw (CWE-94) that lets an unauthenticated attacker run arbitrary code remotely. CISA added it to the KEV on 2026-04-08, due 2026-04-11 (3 days). The CVSS published on NVD is 9.8 (CRITICAL).

Key facts

  • CVE IDCVE-2026-1340
  • CVSS base score9.8 CRITICAL
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Affected (vendor / product)Ivanti Endpoint Manager Mobile (EPMM)
  • CWECWE-94
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-04-11 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Code injection (CWE-94) in Ivanti EPMM (formerly MobileIron Core) — unauthenticated remote code execution.
  • The vector is PR:N and UI:N — no privilege and no user interaction required. The CVSS published on NVD is 9.8 (CRITICAL).
  • An MDM platform is the distribution source to the device fleet — a single breach can spread to the whole company's mobile estate.
  • EPMM is often internet-facing and thus easy to reach; Ivanti products are KEV regulars.
  • CISA added it to the KEV on 2026-04-08, due 2026-04-11 (3 days), and asks for a check for signs of compromise.

Code injection (CWE-94) is a flaw in which an attacker slips code (commands) into input that should be treated purely as data, and the system executes it. Without adequate validation and separation of input, an attacker can run the injected code on the server — effectively taking over the machine.

What makes this severe is that it is said to be possible on Ivanti EPMM without authentication (no login), as the vector's PR:N (no privilege required) and UI:N (no user interaction) confirm.

That the target is an MDM (mobile-device-management) platform is decisive for the weight of this flaw. EPMM functions as the distribution source that pushes settings, certificates, and apps to the many smartphones and tablets an organization deploys.

Seize that source without authentication and the impact is not confined to one device but can propagate across the entire managed fleet — a single breach spreading to the whole company's mobile estate. EPMM is also often placed facing the internet so that devices outside the office can check in at any time, making it easy for attackers to reach.

Ivanti products (EPMM, Connect Secure, and others) have been KEV regulars in recent years, emblematic of how boundary and management products are targeted again and again. CISA set the remediation window to just three days after the addition and additionally asks organizations to "check for signs of compromise" — i.e., respond on the assumption that exploitation is already underway.

The response is prompt updating per Ivanti's guidance, together with checking whether compromise has occurred.

Why it matters

Unauthenticated code execution on an MDM platform has an extremely wide blast radius, propagating across the entire managed device fleet. EPMM is often internet-facing and will be targeted continuously if left unaddressed. CISA pairing a 3-day deadline with a request to check for signs of compromise indicates the response must assume exploitation is already advancing. Prompt updating per Ivanti's guidance, together with verifying impact and strengthening monitoring, is the key point.

FAQ

What is code injection?
A flaw where an attacker slips commands into input that should be treated as data and the system executes them. With insufficient validation/separation of input, the injected code runs on the server, leading to takeover of the machine.
Why is targeting an MDM platform a problem?
An MDM is the distribution source that pushes settings, certificates, and apps to many devices. Seize it and the damage is not confined to one device but can propagate across the entire managed fleet, making the impact especially large.
Could it already be exploited?
CISA added it to the KEV (flaws confirmed exploited in the wild) and asks organizations to check for signs of compromise. Respond on the assumption exploitation is already underway, updating and verifying impact promptly.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Ivanti#EPMM#MobileIron#CWE-94#Code Injection#MDM#KEV
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.