Internet-Exposed Ivanti EPMM Appliances Face Active RCE Exploits
Ivanti Endpoint Manager Mobile (EPMM) appliances exposed to the internet remain at critical risk due to an unauthenticated remote code execution vulnerability (CVE-2026-1340) actively exploited since January. The vendor's claim of only a "very limited number" of exploited systems at disclosure misses the broader exposure, as nearly 950 EPMM IPs are still publicly reachable, indicating a large patch gap. This is not an isolated bug but part of a pattern of multiple critical, exploited code-injection flaws in the same product, making the risk systemic for internet-facing deployments.
CISA has mandated U.S. federal agencies to patch this vulnerability within days, underscoring the urgency due to ongoing exploitation. Ivanti released patches on January 29, but Shadowserver's tracking shows hundreds of EPMM appliances remain internet-exposed, mostly in Europe and North America, with no clear data on patch status. The vulnerability allows unauthenticated attackers to execute code remotely on management appliances, posing a direct threat to organizations running unpatched, internet-facing EPMM instances.
The persistence of exposed and unpatched EPMM appliances months after disclosure signals a systemic risk that extends beyond routine patching cycles. Organizations must recognize that this vulnerability is not a one-off incident but part of a recurring pattern of critical flaws in Ivanti EPMM, increasing the likelihood of compromise for any internet-exposed appliance. The risk is highest for U.S. government and regulated entities, where the KEV deadline and active exploitation converge to create a critical security imperative.