Affected Systems
Ivanti Endpoint Manager Mobile (EPMM) products. Specific affected versions not provided in advisory summary. Two critical vulnerabilities enabling unauthenticated remote code execution.
Exploitation Status
Active exploitation confirmed in limited cases for at least one of the two vulnerabilities. Exploitation is unauthenticated and remote.
Business Impact
Organizations running Ivanti EPMM face immediate risk of complete system compromise via unauthenticated RCE. Attackers can execute arbitrary code without credentials, potentially leading to data exfiltration, lateral movement, and persistent access to mobile device management infrastructure. Limited exploitation indicates targeted attacks may be underway. CVE identifiers not yet assigned.
Urgency
🔴 Immediate
Recommended Actions
- Apply Ivanti security patches released on 29 January 2026 immediately to all EPMM instances
- Isolate EPMM servers from internet exposure if patching cannot be completed within 24 hours
- Review EPMM access logs for suspicious unauthenticated connection attempts and unusual administrative activity since early January 2026
- Conduct forensic analysis on EPMM systems for indicators of compromise if exploitation is suspected
- Monitor Ivanti security advisory page for updated IOCs, CVE assignments, and additional mitigation guidance
