Ivanti EPMM Pre-Auth Remote Code Execution (CVE-2026-1281 / CVE-2026-1340) — Threadlinqs Intelligence
As of 2026-05-30, Ivanti EPMM Pre-Auth Remote Code Execution (CVE-2026-1281 / CVE-2026-1340) is a critical-severity vulnerability threat attributed to a China-nexus actor, tracked by Threadlinqs Intelligence with 15 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 55 indicators of compromise.
Threat ID: TL-2026-0002 · Severity: CRITICAL · CVSS: 9.8 · Status: MONITORING · Category: VULNERABILITY
Attribution: China · ESPIONAGE
CVE-2026-1281 is a critical pre-authentication Remote Code Execution (RCE) vulnerability in Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core), affecting versions prior to 12.3.0.1. The
CVE-2026-1281 represents the continuation of a persistent pattern: Ivanti enterprise security products being compromised to gain access to the organizations they are supposed to protect.
**The Product — Ivanti EPMM:**
Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core, is an enterprise Mobile Device Management (MDM) platform that:
- Manages and secures mobile device fleets (iOS, Android, Windows) across enterprises
- Controls device enrollment, configuration profiles, app deployment, and security policies
- Stores device credentials (WiFi, VPN, email configurations)
- Provides remote lock, wipe, and location tracking capabilities
- Used by Fortune 500 companies, government agencies, defense organizations, and military
- Deployed as an on-premises appliance or cloud-hosted service
- Manages thousands to hundreds of thousands of devices per deployment
Compromising the EPMM server is equivalent to compromising EVERY mobile device it manages.
**The Vulnerability — CVE-2026-1281:**
- **Type**: Pre-authentication Remote Code Execution
- **CVSS**: 9.8 (Critical)
- **Vector**: Network-accessible API endpoint, no credentials required
- **Root Cause**: Improper input validation in the device enrollment API leading to deserialization of untrusted data
- **Exploitation**: Crafted HTTP request to the enrollment endpoint triggers code execution as root/SYSTEM on the EPMM appliance
- **Complexity**: Low — reliable exploitation achievable with single HTTP request
- **Affected Versions**: Ivanti EPMM prior to 12.3.0.1
- **Patch Available**: Yes — Ivanti EPMM 12.3.0.1 and later
**Exploitation in the Wild:**
Active exploitation was detected targeting:
- Government agencies in Europe and North America
- Defense contractors managing classified device fleets
- Healthcare organizations managing clinical devices
- Financial institutions managing corporate mobile fleets
The exploitation pattern matches sophisticated, targeted operations:
- Scanning for exposed EPMM instances on internet-facing management interfaces
- Single-request exploitation achieving root access
- Post-exploitation: enumeration of managed device fleet, extraction of configuration profiles, deployment of persistent backdoors
- Evidence of follow-on activity against managed mobile devices (configuration profile manipulation, credential extraction)
**Post-Exploitation Impact — MDM as Pivot:**
1. **Device Fleet Control**: Attacker gains administrative control over ALL managed mobile devices — can push malicious profiles, extract credentials, deploy surveillance
2. **Credential Harvest**: MDM stores WiFi credentials, VPN configurations, email account settings, certificate private keys — all extractable from compromised server
3. **Location Surveillance**: MDM can track real-time location of all enrolled devices — intelligence goldmine for state-sponsored actors targeting government officials
4. **Communication Access**: Managed email profiles grant access to organizational email through device management APIs
5. **Lateral Movement**: MDM server sits at the intersection of mobile and enterprise networks — compromised server enables network pivoting
6. **Remote Wipe Weapon**: Attacker can remotely wipe ALL managed devices simultaneously — destructive capability affecting thousands of devices
7. **Persistent Access**: Backdoors on MDM server persist through mobile device policy updates, affecting all future device enrollments
**Ivanti Product Exploitation History:**
Ivanti products represent a PATTERN of strategic compromise:
- **CVE-2023-35078 + CVE-2023-35081** (Jul 2023): EPMM/MobileIron pre-auth access + RCE. Exploited against Norwegian government ministries.
- **CVE-2024-21887 + CVE-2023-46805** (Jan 2024): Connect Secure VPN auth bypass + RCE chain. Mass exploitation by multiple threat actors including suspected Chinese state-sponsored groups.
- **CVE-2024-8963** (Sep 2024): Cloud Services Appliance (CSA) admin bypass. Chained with other vulns for full compr
Target sectors: Government, Defense, Healthcare, Financial Services, Technology
Target regions: Europe, North America, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 15 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 55 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-1281, CVE-2026-1340, T1190, T1059.004, T1505.003, T1098, T1070.002, T1552.001, T1082, T1087, T1213, T1210