Ivanti Endpoint Manager Mobile zero-day exploitation, European government breaches, and concentrated attack wave
Case score 71
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 71
- Main story score
- 64
- Related evidence lift
- +0 / 20
- Contributing updates
- 3
- Context updates
- 1
- Vulnerability Anchor event for the exploited Ivanti EPMM flaws, zero-day activity, affected versions, and response timeline. main
- Campaign Adds coordinated European government breach context, broader data exposure, and follow-on risk. contributes
- Security Patch Release Adds vendor fixes, KEV urgency, and the upgrade caveat for the same EPMM exposure. context
- Incident Adds confirmed European Commission fallout and limited staff-data exposure from the same exposure. contributes
-
Old: Ivanti Endpoint Manager Mobile zero-day exploitation, European government data theft, and concentrated exploitation waveNew: Ivanti Endpoint Manager Mobile zero-day exploitation, European government breaches, and concentrated attack waveWhy old title changed: The previous title leaned on a data-theft framing and did not fully reflect the later, more specific breach disclosures and the concentrated February attack wave now visible in the record.The new title better matches the current evidence by foregrounding confirmed European government breaches and the sustained attack wave without overcommitting to a theft-only interpretation.
-
Old: Ivanti Endpoint Manager Mobile zero-day exploitation and European government data theft campaignNew: Ivanti Endpoint Manager Mobile zero-day exploitation, European government data theft, and concentrated exploitation waveWhy old title changed: The prior title captured the zero-day exploitation and European government fallout, but it did not reflect the later concentrated wave of live targeting against the same exposure.The new title keeps the product and fallout framing while adding the active exploitation wave that now shapes current reader priority.
-
Old: Ivanti Endpoint Manager Mobile zero-day exploitation and European public-sector compromiseNew: Ivanti Endpoint Manager Mobile zero-day exploitation and European government data theft campaignWhy old title changed: The earlier title captured exploitation and public-sector compromise, but it no longer reflected the coordinated multi-institution campaign and broader government data exposure now confirmed.The new title keeps the exploited EPMM flaws front and center while better capturing the campaign-style fallout and government data exposure that now define the story.
-
Old: Ivanti Endpoint Manager Mobile zero-day exploitation of critical code-injection flawsNew: Ivanti Endpoint Manager Mobile zero-day exploitation and European public-sector compromiseWhy old title changed: The earlier title captured the flaws and exploitation but no longer fully reflected the confirmed European public-sector compromise that followed.The new title keeps the EPMM zero-day focus while better signaling the now-confirmed public-sector fallout and reader priority.
Overview
Latest development Open development history CISA adds CVE-2026-1281 to the KEV catalog CISA added CVE-2026-1281 to the Known Exploited Vulnerabilities (KEV) catalog, and Federal Civilian Executive Branch (FCEB) agencies must apply the updates by February 1, 2026. The policy action raises remediation urgency for Ivanti Endpoint Manager Mobile (EPMM) deployments exposed to the actively exploited zero-day flaw.
-
Ivanti EPMM campaign sees Feb. 9 attack spike against European governments
Shadowserver tracked another more voluminous wave of attempted attacks against European government targets around Feb. 9, 2026, and Greynoise said 83% of the exploitation spike came from a single IP address on a bulletproof hosting service rather than the IOCs Ivanti published.
-
Ivanti EPMM attacks hit European Commission and government agencies
Reported on Feb. 12, 2026, attacks tied to Ivanti Endpoint Manager Mobile (EPMM) had struck the European Commission and agencies of the Dutch and Finnish governments after Ivanti disclosed CVE-2026-1281 and CVE-2026-1340 on Jan. 29. The European Commission said its central infrastructure managing mobile devices was hit on Jan. 30, with staff names and mobile numbers compromised, while Valtori said an attack of the same nature affected around 50,000 people associated with Finland's central government and leaked names, email addresses, phone numbers, and other device details.
-
Ivanti discloses EPMM zero-days and patches
Ivanti released patches for two critical CVSS 9.8 zero-day code-injection flaws in Ivanti Endpoint Manager Mobile (EPMM), identified as CVE-2026-1281 and CVE-2026-1340, and warned that a very limited number of customers had already seen exploitation at the time of disclosure.
-
European Commission discloses the breach investigation
The European Commission disclosed that it is investigating a breach after finding evidence that its mobile device management platform was hacked, and said the compromise appears linked to similar attacks on European institutions exploiting Ivanti Endpoint Manager Mobile (EPMM) vulnerabilities.