Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Is This Poker Player Bluffing? The AI Thinks So

    August 4, 2026

    The Download: US robot restrictions, and ICE’s DNA grab

    August 4, 2026

    ‘Everyone Is Doing It’: The Truth About AI in Hollywood

    August 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Is This Poker Player Bluffing? The AI Thinks So
    • The Download: US robot restrictions, and ICE’s DNA grab
    • ‘Everyone Is Doing It’: The Truth About AI in Hollywood
    • Did an AI Music App Just Snitch on the Song of the Summer?
    • Trump’s AI protectionism has come for robotics
    • Turning Paper Charts Into Digital Medical Records
    • The ‘Guardrail Guy’ Went Viral for Posting About Flock Cameras. Then Someone Destroyed Them
    • The Download: reward hacking explained, and suspected Iranian cyberattacks
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Ivanti’s January bad luck continues as 0-days hit customers • The Register
    Cybersecurity

    Ivanti’s January bad luck continues as 0-days hit customers • The Register

    kirklandc008@gmail.comBy kirklandc008@gmail.comJanuary 31, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Ivanti's January bad luck continues as 0-days hit customers • The Register
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ivanti has patched two critical zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM) product that are already being exploited, continuing a grim run of January security incidents for enterprise IT vendors.

    In January 2025, tens of thousands were urged to patch a Fortinet zero-day, while Ivanti customers were doing the same. There has been little change this year as Fortinet patches multiple single sign-on (SSO) flaws and Ivanti ships fixes for yet another pair of zero-days.

    Tracked as CVE-2026-1281 and CVE-2026-1340, both bugs affect Ivanti Endpoint Manager Mobile (EPMM). They’re also both rated a near-maximum CVSS score of 9.8 and allow for unauthenticated remote code execution (RCE) – about as bad as it gets.

    The security shop said in its advisory: “We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure.

    “This vulnerability does not impact any other Ivanti products, including any cloud products, such as Ivanti Neurons for MDM. Ivanti Endpoint Manager (EPM) is a different product and also not impacted by these vulnerabilities. Customers using an Ivanti cloud product with Sentry are also not impacted by this vulnerability.”

    These kinds of RCE bugs can lead to all sorts of nastiness. Lateral movement across a given organization’s network, config changes, and attackers making themselves admin are all possible. The vendor warned that it could grant access to certain data too.

    Ivanti said that the types of information available could include basic personal information about the EPMM admin and device user, as well as information about mobile devices such as phone numbers and GPS locations.

    Those looking for indicators of compromise (IOCs) are out of luck. Ivanti doesn’t have any reliable ones due to the small number of impacted customers it knows about.

    It does, however, have a technical analysis page, which includes more general information about how to detect potential exploits.

    The Apache access log is a good place to start for threat hunters. Specifically, they should be looking at the In-House Application Distribution and the Android File Transfer Configuration features. Legitimate traffic leads to 200 HTTP response codes while potential exploit activity may result in 404s.

    “We recommend reviewing these and any other GET requests with parameters that have bash commands,” Ivanti said.

    This is not the first time in recent memory that EPMM has been hit by RCE bugs, and previous analyses have shown attackers tend to use two common methods of persistence. More often than not, it’s introducing or modifying web shells, typically targeting error pages such as 401.jsp, the vendor said.

    “Any requests to these pages with POST methods or with parameters should be considered highly suspicious.”

    Ivanti also advised defenders to look out for unexpected WAR or JAR files being introduced to the system, as it could be a sign of attackers deploying reverse shell connections.

    EPMM also does not usually make outbound network connections, so any signs of this in the firewall logs should be treated as a sign to investigate.

    If a customer does find signs of compromise, Ivanti said it’s best to just restore from backups – don’t bother trying to clean the system – and then upgrade to the latest relevant version.

    Alternatively, if going down the backup route isn’t an option, Ivanti suggests building a replacement EPMM device and migrating data onto it.

    Benjamin Harris, CEO at watchTowr, said that a “wide range” of its customers who have EPMM running belong to high-value industries, warning others to act fast.

    He said: “We knew January seemed too calm. Ivanti’s EPMM solution, the center point of previous zero-day sagas, is once again receiving in-the-wild exploitation by seemingly capable and well-resourced threat actors.

    “CVE-2026-1281 and CVE-2026-1340 – unauthenticated RCE vulnerabilities within Ivanti’s Endpoint Manager Mobile (EPMM) – represent the worst of the worst, with threat actors actively compromising systems and deploying backdoors.

    “While patches are available from Ivanti, applying patches will not be enough. Threat actors have been exploiting these vulnerabilities as zero-days, and organizations that are, as of disclosure, exposing vulnerable instances to the internet must consider them compromised, tear down infrastructure, and instigate incident response processes.” ®

    0days Bad continues Customers hit Ivantis January Luck Register
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

    August 1, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Is This Poker Player Bluffing? The AI Thinks So
    • The Download: US robot restrictions, and ICE’s DNA grab
    • ‘Everyone Is Doing It’: The Truth About AI in Hollywood
    • Did an AI Music App Just Snitch on the Song of the Summer?
    • Trump’s AI protectionism has come for robotics

    Is This Poker Player Bluffing? The AI Thinks So

    August 4, 2026

    The Download: US robot restrictions, and ICE’s DNA grab

    August 4, 2026

    ‘Everyone Is Doing It’: The Truth About AI in Hollywood

    August 4, 2026

    Did an AI Music App Just Snitch on the Song of the Summer?

    August 4, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.