Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Campaign Exploitation Wave Incident Security Patch Release

Ivanti Endpoint Manager Mobile zero-day exploitation, European government breaches, and concentrated attack wave

Updated 08.04.2026 21:15
Case score 71
Members 5 First seen 30.01.2026 06:43 Latest activity 08.04.2026 21:15

Overview

**Ivanti Endpoint Manager Mobile (EPMM)** remains under active zero-day exploitation for **CVE-2026-1281** and **CVE-2026-1340**, two critical code-injection flaws that allow unauthenticated remote code execution. A concentrated February exploitation wave later logged **417 sessions** from eight source IPs, and Shadowserver tracked a more voluminous Feb. 9 burst against European government targets. Confirmed fallout reaches the **European Commission**, the **Finnish government**, and at least two Dutch agencies, with staff contact details and device information exposed in some incidents. Patches are available, **CISA** has placed both flaws in the **KEV catalog** with federal deadlines on **February 1** and **April 11**, and compromise review remains warranted for exposed deployments.
Latest development Open development history 4 earlier developments CISA adds CVE-2026-1281 to the KEV catalog CISA added CVE-2026-1281 to the Known Exploited Vulnerabilities (KEV) catalog, and Federal Civilian Executive Branch (FCEB) agencies must apply the updates by February 1, 2026. The policy action raises remediation urgency for Ivanti Endpoint Manager Mobile (EPMM) deployments exposed to the actively exploited zero-day flaw.
  1. Earlier development

    Ivanti EPMM campaign sees Feb. 9 attack spike against European governments

    Shadowserver tracked another more voluminous wave of attempted attacks against European government targets around Feb. 9, 2026, and Greynoise said 83% of the exploitation spike came from a single IP address on a bulletproof hosting service rather than the IOCs Ivanti published.

  2. Earlier development

    Ivanti EPMM attacks hit European Commission and government agencies

    Reported on Feb. 12, 2026, attacks tied to Ivanti Endpoint Manager Mobile (EPMM) had struck the European Commission and agencies of the Dutch and Finnish governments after Ivanti disclosed CVE-2026-1281 and CVE-2026-1340 on Jan. 29. The European Commission said its central infrastructure managing mobile devices was hit on Jan. 30, with staff names and mobile numbers compromised, while Valtori said an attack of the same nature affected around 50,000 people associated with Finland's central government and leaked names, email addresses, phone numbers, and other device details.

  3. Earlier development

    Ivanti discloses EPMM zero-days and patches

    Ivanti released patches for two critical CVSS 9.8 zero-day code-injection flaws in Ivanti Endpoint Manager Mobile (EPMM), identified as CVE-2026-1281 and CVE-2026-1340, and warned that a very limited number of customers had already seen exploitation at the time of disclosure.

  4. Earlier development

    European Commission discloses the breach investigation

    The European Commission disclosed that it is investigating a breach after finding evidence that its mobile device management platform was hacked, and said the compromise appears linked to similar attacks on European institutions exploiting Ivanti Endpoint Manager Mobile (EPMM) vulnerabilities.

Signals

Impact signals
Exploitation
Affected impact
CVEs/products
Geographic context
Remediation
Status

Malware & tooling context

6 families · 1 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability Ivanti Endpoint Manager Mobile (EPMM) actively exploited code injection flaws (multiple vulnerabilities)
Updated 30.01.2026 06:43 Lead Contribution 64
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**Ivanti Endpoint Manager Mobile (EPMM)** is affected by **two critical code-injection flaws** — **CVE-2026-1281** and **CVE-2026-1340** — that enable **unauthenticated remote code execution** and were **exploited in zero-day attacks**. **Ivanti** has released updates, and **CISA** added **CVE-2026-1281** to the **KEV catalog**, making the issue urgent for exposed deployments.

Campaign Ivanti EPMM mobile-data theft campaign targeting European governments
Updated 10.02.2026 11:45 Scoring Support Contribution 3
Objective Espionage Campaign Active Patch Patch Available

A **coordinated Ivanti EPMM campaign** is now linked to breaches at multiple **European government** bodies, raising concern that staff and mobile-user data were exposed across several institutions. The activity reached the **European Commission**, the **Finnish government**, and **at least two Dutch agencies** during **January 29-February 6, 2026**. The exposure matters because compromised mobile-management data can enable follow-on **spearphishing** and impersonation against government users.

Incident European Commission hit by cyberattack
Updated 09.02.2026 11:49 Scoring Support Contribution 2
Extortion None Incident Contained

The **European Commission** is investigating a **cyberattack** on its **mobile device management platform**, which may have exposed staff **names** and **mobile numbers**. The incident was **contained** and cleaned within **9 hours**, limiting the immediate operational impact. The breach matters because it may be connected to wider attacks on **European institutions** using **Ivanti Endpoint Manager Mobile (EPMM)** zero-day flaws.

Exploitation Wave Ivanti EPMM exploitation wave (CVE-2026-1281)
Updated 12.02.2026 09:32 Scoring Support Contribution 2
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**Ivanti Endpoint Manager Mobile (EPMM)** is facing an **active exploitation wave** against **CVE-2026-1281** and **CVE-2026-1340**, creating immediate risk for internet-facing management systems. GreyNoise observed **417 exploitation sessions** from **8 source IPs** between **February 1 and 9, 2026**. A single host, **193.24.123[.]42**, generated **346 sessions** and accounted for **83%** of the attempts. Ivanti said a **very limited number of customers** were impacted after **zero-day exploitation**, showing the abuse had already moved beyond disclosure into live targeting.

Security Patch Release Ivanti security patch release for CVE-2026-1281
Updated 30.01.2026 06:43 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency High Patch Patch Available

**Ivanti** released **security updates** for **Ivanti Endpoint Manager Mobile (EPMM)** after disclosure of **two critical zero-day flaws** that can enable **unauthenticated remote code execution**. The patch set covers **CVE-2026-1281** and **CVE-2026-1340** on affected **EPMM 12.5.0.0 and prior, 12.6.0.0 and prior, 12.7.0.0 and prior**, with a permanent fix planned for **12.8.0.0**. **CISA** also added **CVE-2026-1281** to the **KEV catalog**, making timely remediation especially urgent.