References https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340 https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US https://hub.ivanti.com/s/article/Analysis-Guidance-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340 https://blog.nsfocus.net/%E3%80%90%E6%BC%8F%E6%B4%9E%E9%80%9A%E5%91%8A%E3%80%91ivanti-endpoint-manager-mobile%E8%BA%AB%E4%BB%BD%E9%AA%8C%E8%AF%81%E7%BB%95%E8%BF%87%E4%B8%8E%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7/ https://www.gm7.org/archives/38014 https://www.ithome.com.tw/news/173694 https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/ https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=12705 https://www.rapid7.com/blog/post/etr-critical-ivanti-endpoint-manager-mobile-epmm-zero-day-exploited-in-the-wild-eitw-cve-2026-1281-1340/ https://www.greynoise.io/blog/ivanti-epmm-zero-days-reconnaissance-exploitation https://hub.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability https://nvd.nist.gov/vuln/detail/cve-2023-35078 https://zeropath.com/blog/cve-2026-5788-ivanti-epmm-improper-access-control https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-1281 https://www.secrss.com/articles/78714 https://www.anquanke.com/post/id/307365 https://www.cv.ncu.edu.tw/202602021400/ https://avd.aliyun.com/detail?id=AVD-2026-5787 https://www.greynoise.io/blog/ivanti-epmm-zero-days-reconnaissance-exploitation
Related VulnerabilitiesPoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code InjectionPoCCVE-2026-10520: Ivanti Sentry - OS Command InjectionIvanti Sentry存在操作系统命令注入漏洞(CVE-2026-10520)Ivanti Sentry /mics/api/v2/sentry/mics-config/handleMessage 命令执行漏洞(CVE-2026-10520)Ivanti EPMM /mifs/rs/api/v2/featureusage 命令执行漏洞(CVE-2025-4427)PoCIvanti Endpoint Manager /RemoteControlAuth/api/Auth 权限绕过漏洞(CVE-2026-1603)Ivanti Endpoint Manager 权限管理不当漏洞PoCCVE-2026-1603: Ivanti Endpoint Manager - Authentication BypassIvanti Endpoint Manager Mobile /mifs/c/appstore/fob/3/5/sha256 命令执行漏洞(CVE-2026-1281/CVE-2026-1340)Ivanti Endpoint Manager Mobile 未授权 代码注入漏洞Ivanti多个产品跨站请求伪造漏洞(CVE-2025-8711)(CVE-2025-8712)Ivanti产品权限验证不足漏洞