Two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in Ivanti Endpoint Manager Mobile are being actively exploited to achieve remote code execution on MDM servers. The flaws stem from unsafe bash arithmetic expansion in legacy Apache RewriteMap scripts. Attackers are deploying web shells, reverse shells,

9m read time From unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryDetails of CVE-2026-1281Details of CVE-2026-1340Current Scope of the ExploitationInterim Guidance for CVE-2026-1281 and CVE-2026-1340Unit 42 Managed Threat Hunting QueriesConclusionPalo Alto Networks Product Protections for CVE-2026-1281 and CVE-2026-1340Indicators of Compromise

Sort: