Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch Government Breached, Bulletproof Hosting IAB, Sleeper Webshells, 28K+ Attacking IPs — Threadlinqs Intelligence
As of 2026-07-19, Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch Government Breached, Bulletproof Hosting IAB, Sleeper Webshells, 28K+ Attacking IPs is a critical-severity vulnerability threat attributed to UNC5221 (China), tracked by Threadlinqs Intelligence with 12 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 63 indicators of compromise.
Threat ID: TL-2026-0121 · Severity: CRITICAL · CVSS: 9.8 · Status: PATCHED · Category: VULNERABILITY
Updated: 2026-07-19 · 2 updates · revalidated 2× · latest source
Attribution: UNC5221 · China · financial
Dual CVSS 9.8 unauthenticated RCE vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) under mass exploitation by initial access broker on bulletproof hosting, with confirmed Dutch government
CVE-2026-1281 and CVE-2026-1340 are two critical code injection vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 through 12.7.0.0. CVE-2026-1281 exploits Bash arithmetic expansion in EPMM's file delivery mechanism at the /mifs/c/appstore/fob/ endpoint, allowing unauthenticated attackers to inject malicious payloads via URL parameters and execute arbitrary commands as the web server user. CVE-2026-1340 is a related code injection flaw in a different EPMM component (aftstore vs appstore packages). Both carry CVSS 9.8, require no authentication, and enable full remote code execution.
The exploitation campaign exhibits strong initial access broker (IAB) characteristics. GreyNoise telemetry recorded 417 exploitation sessions from 8 IPs between Feb 1-9, with 83% (346 sessions) originating from a single IP (193.24.123.42) on PROSPERO OOO bulletproof hosting (AS200593, Saint Petersburg, Russia). This IP was notably absent from widely published IOC lists, meaning defenders blocking only published indicators missed the dominant exploitation source. The IP simultaneously exploits four unrelated CVEs across Oracle WebLogic, GNU telnetd, Ivanti EPMM, and GLPI, rotating through 300+ user-agent strings — consistent with automated mass exploitation tooling.
85% of exploitation payloads used OAST (Out-of-Band Application Security Testing) DNS callbacks to verify command execution without immediately deploying malware — cataloging vulnerable targets for later exploitation rather than immediate compromise. Defused Cyber independently confirmed this IAB pattern: attackers deployed dormant in-memory Java class loaders to /mifs/403.jsp that wait for a specific trigger parameter (k0f53cf964d387) to activate. The implant (base.Info, compiled from Info.java) uses equals(Object) as entry point instead of standard servlet methods to evade detection, supports both modern and legacy JVMs, and fingerprints the host before handing off to a second-stage class loaded entirely in memory via ClassLoader#defineClass.
Dutch government institutions were confirmed compromised: the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) and the Council for the Judiciary (Raad voor de Rechtspraak, RVDR) were breached before most organizations had patched. Shadowserver observed 28,300+ unique source IPs attempting exploitation on Feb 9, with 72% from US-based infrastructure, followed by UK (3,800 IPs) and Russia (1,900 IPs). 56 IPs were confirmed compromised with webshells.
The exploitation timeline was unprecedented: Ivanti advisory, CISA KEV listing, and confirmed government compromise all occurred on January 29 — the same day. watchTowr Labs published full technical analysis by January 30, and PoC code appeared on GitHub shortly after. CISA issued an unprecedented 3-day remediation deadline. NHS England, CERT-EU, and NCSC-NL issued advisories confirming active exploitation.
EPMM manages mobile devices, applications, and content across enterprise environments. Successful compromise provides attackers with extensive control over corporate mobile infrastructure, including the ability to deploy additional payloads to managed devices and facilitate lateral movement — making MDM platforms equivalent in criticality to domain controllers. Ivanti has released temporary RPM patches for affected versions, with a permanent fix scheduled for version 12.8.0.0 in Q1 2026. The vendor recommends rebuilding EPMM environments and migrating data as the most conservative remediation.
Weaknesses (CWE)
CWE-94, CWE-95, CWE-78
Target sectors: government, enterprise, technology, healthcare, education
Target regions: Netherlands, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 12 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 63 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-1281, CVE-2026-1340, T1190, T1059.004, T1203, T1505.003, T1525, T1027, T1140, T1070.004, T1620, T1480