CVE-2026-1340CRITICAL 9.8CISA KEVEPSS p99.6%

CVE-2026-1340Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti / Endpoint Manager Mobile (EPMM)

Description

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS82.00% probability of exploitation · percentile 99.6% · 2026-06-17T12:03:21Z
Published2026-01-29
Last modified2026-04-09

CISA KEV entry

Added to KEV: 2026-04-08

Underlying weaknesses· 1

CWE-94

References

  1. https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-1340

1

TypeTargetConfidenceTier
WeaknessImproper Control of Generation of Code ('Code Injection')cwe-940%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryIvanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerabilitykev-cve-2026-13400%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-10727
CVE
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
CVE
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
CVE
Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability
CVE
CVE-2026-8111
CVE
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.