9.8 CVE-2026-1281

CISA Kev Catalog Patch
 

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
https://nvd.nist.gov/vuln/detail/CVE-2026-1281

Categories

CWE-94

References

134c704f-9b21-4f2e-91b3-4a467353bcc0

3c1d8aa1-5a33-4ea4-8992-aadd6440af75 Patch


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* <= 12.5.0.0
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.7.0.0:*:*:*:*:*:*:*


REMEDIATION


Patch

Url
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager...


EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry